Latest CVE Feed
-
2.1
LOWCVE-2010-2574
Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.... Read more
Affected Products : mantisbt- EPSS Score: %0.42
- Published: Aug. 10, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-2100
The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).... Read more
- EPSS Score: %0.06
- Published: Oct. 25, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-1716
CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files.... Read more
Affected Products : safari- EPSS Score: %0.10
- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2005-1913
The Linux kernel 2.6 before 2.6.12.1 allows local users to cause a denial of service (kernel panic) via a non group-leader thread executing a different program than was pending in itimer, which causes the signal to be delivered to the old group-leader tas... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Sep. 14, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-3427
EC2 Amazon Machine Image (AMI) in JBoss Enterprise Application Platform (EAP) 5.1.2 uses 755 permissions for /var/cache/jboss-ec2-eap/, which allows local users to read sensitive information such as Amazon Web Services (AWS) credentials by reading files i... Read more
Affected Products : jboss_enterprise_application_platform- EPSS Score: %0.05
- Published: Feb. 02, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-5549
Unspecified vulnerability in Command EXEC in Cisco IOS allows local users to bypass command restrictions and obtain sensitive information via an unspecified "variation of an IOS command" involving "two different methods", aka CSCsk16129. NOTE: as of 2007... Read more
Affected Products : ios- EPSS Score: %0.06
- Published: Oct. 18, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2005-2451
Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.... Read more
- EPSS Score: %3.04
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2509
Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts.... Read more
- EPSS Score: %0.08
- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-3221
Unspecified vulnerability in the Oracle VM Virtual Box component in Oracle Virtualization 3.2, 4.0, and 4.1 allows local users to affect availability via unknown vectors related to VirtualBox Core. NOTE: The previous information was obtained from the Oct... Read more
- EPSS Score: %0.40
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-3205
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity via unknown vectors related to Vino server.... Read more
- EPSS Score: %0.06
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-2196
The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.... Read more
Affected Products : airport_card- EPSS Score: %0.07
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2240
xpvm.tcl in xpvm 1.2.5 allows local users to overwrite arbitrary files via a symlink attack on the xpvm.trace.$user temporary file.... Read more
Affected Products : xpvm- EPSS Score: %0.10
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-3146
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : database_server- EPSS Score: %0.17
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-3718
Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 allows local users to read passwords entered into Login Window (aka LoginWindow) or Screen Saver Unlock by installing an input method that intercepts keystrokes.... Read more
- EPSS Score: %0.06
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-2554
The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.... Read more
Affected Products : epolicy_orchestrator_agent- EPSS Score: %0.05
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-4271
Directory traversal vulnerability in IBM DB2 UDB 8 before Fixpak 15 and 9.1 before Fixpak 3 allows local users to create arbitrary files via a .. (dot dot) in an unspecified environment variable, which is appended to "/tmp/" and used as a log file. NOTE:... Read more
Affected Products : db2_universal_database- EPSS Score: %0.05
- Published: Aug. 18, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-4656
backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its a... Read more
Affected Products : backup_manager- EPSS Score: %0.07
- Published: Sep. 04, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2011-3196
The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apache2.conf, which allows local users to obtain the dtcdaemons MySQL password by reading the file.... Read more
Affected Products : domain_technologie_control- EPSS Score: %0.05
- Published: Mar. 21, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-1976
Cross-site scripting (XSS) vulnerability in the Taxonomy Breadcrumb module 6.x before 6.x-1.1 for Drupal allows remote authenticated users, with administer taxonomy permissions, to inject arbitrary web script or HTML via the node title in a Breadcrumb dis... Read more
- EPSS Score: %0.25
- Published: May. 19, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-3982
The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a de... Read more
Affected Products : aix- EPSS Score: %0.07
- Published: Oct. 05, 2011
- Modified: Apr. 11, 2025