Latest CVE Feed
-
2.1
LOWCVE-2014-4702
The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4701.... Read more
Affected Products : nagios- EPSS Score: %0.11
- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-6501
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via vectors related to SSH.... Read more
- EPSS Score: %0.06
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-0640
Orbicule Undercover allows attackers with physical or root access to disable the protection by using the chmod command to change the permissions of the /private/etc/uc.app/Contents/MacOS/uc file, which prevents the service from being started in LaunchDaem... Read more
Affected Products : undercover- EPSS Score: %0.05
- Published: Feb. 10, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-5247
The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API ... Read more
- EPSS Score: %0.07
- Published: Aug. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2008-0580
Geert Moernaut LSrunasE and Supercrypt use an encryption key composed of an SHA1 hash of a fixed string embedded in the executable file, which makes it easier for local users to obtain this key without reverse engineering.... Read more
- EPSS Score: %0.03
- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-0570
The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key.... Read more
- EPSS Score: %0.12
- Published: Jul. 03, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-0976
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained fr... Read more
Affected Products : silverstripe- EPSS Score: %0.38
- Published: Feb. 02, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2000-0691
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.... Read more
- EPSS Score: %0.25
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-1996
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.... Read more
- EPSS Score: %0.06
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-5482
ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate function on a file type that is not VREG, VLNK or VDIR, which is not defined in POSIX.... Read more
Affected Products : freebsd- EPSS Score: %0.24
- Published: Oct. 24, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2011-3345
ulp/sdp/sdp_proc.c in the ib_sdp module (aka ib_sdp.ko) in the ofa_kernel package in the InfiniBand driver implementation in OpenFabrics Enterprise Distribution (OFED) before 1.5.3 does not properly handle certain non-array variables, which allows local u... Read more
Affected Products : enterprise_distribution- EPSS Score: %0.13
- Published: Sep. 19, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-5202
BazisVirtualCDBus.sys in WinCDEmu 3.6 allows local users to cause a denial of service (system crash) via the unmount command to batchmnt.exe.... Read more
Affected Products : wincdemu- EPSS Score: %0.06
- Published: Oct. 01, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-3878
Opsware Network Automation System (NAS) 6.0 installs /etc/init.d/mysql with insecure permissions, which allows local users to read the root password for the MySQL MAX database or gain privileges by modifying /etc/init.d/mysql.... Read more
Affected Products : network_automation_system- EPSS Score: %0.06
- Published: Jul. 27, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-1123
Chip Salzenberg Deliver does not properly associate a lockfile with the user who created the file, which allows local users to cause a denial of service (blockage of incoming e-mail) by creating lockfiles for arbitrary mailboxes.... Read more
Affected Products : deliver- EPSS Score: %0.04
- Published: Mar. 26, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-1530
Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1)... Read more
- EPSS Score: %0.23
- Published: Apr. 26, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-0991
RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.... Read more
Affected Products : aix- EPSS Score: %0.06
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-2123
Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) address, (3) ... Read more
- EPSS Score: %0.34
- Published: Jun. 01, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-0465
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.... Read more
Affected Products : irix- EPSS Score: %0.24
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-5380
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : maximo_asset_management- EPSS Score: %0.06
- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-0517
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.... Read more
Affected Products : peerftp_5- EPSS Score: %0.18
- Published: Feb. 23, 2005
- Modified: Apr. 03, 2025