Latest CVE Feed
-
2.1
LOWCVE-1999-1229
Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.... Read more
Affected Products : quake_2_server- EPSS Score: %0.06
- Published: Feb. 25, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0690
Gene6 FTP Server does not properly restrict access to the control console, which allows local users to modify the server configuration and gain privileges, as demonstrated by defining a SITE command.... Read more
Affected Products : g6_ftp_server- EPSS Score: %0.09
- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-7835
webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site... Read more
Affected Products : moodle- EPSS Score: %0.18
- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2016-3888
internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, ... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2004-1346
The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.... Read more
Affected Products : solaris- EPSS Score: %0.09
- Published: Jun. 19, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4755
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier (1) stores the private key passphrase (CustomTrustKeyStorePassPhrase) in cleartext in nodemanager.config; or, during domain creation with the Configuration Wizard, renders an SSL private key pas... Read more
Affected Products : weblogic_server- EPSS Score: %0.08
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1578
Unknown vulnerability in SCO OpenServer 5.0.6 and earlier allows local users to modify critical information such as certain CPU registers and segment descriptors.... Read more
Affected Products : openserver- EPSS Score: %0.08
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-3223
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.0.1 allows remote authenticated users to affect confidentiality, related to BASE.... Read more
Affected Products : financial_services_software- EPSS Score: %0.22
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2001-1527
easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access.... Read more
Affected Products : easynews- EPSS Score: %0.06
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1429
DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver.... Read more
Affected Products : transferpro- EPSS Score: %0.08
- Published: Jan. 05, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1520
Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal digital assistant (PDA) via Rextools, and capturing the cleartext PIN.... Read more
Affected Products : xircom_rex_6000- EPSS Score: %0.15
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1251
Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.... Read more
Affected Products : hp-ux- EPSS Score: %0.08
- Published: Dec. 24, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3696
filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows local users to cause a denial of service (crash) via long arguments to mshta.exe.... Read more
Affected Products : outpost_firewall- EPSS Score: %0.30
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-3929
Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject arbitrary web script or HTML via the handler parameter.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.18
- Published: Dec. 09, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-1999-1285
Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Dec. 27, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-1539
Cross-site scripting (XSS) vulnerability in the Workflow module 5.x-2.x before 5.x-2.6 and 6.x-1.x before 6.x-1.4 for Drupal, when used with the Token module, might allow remote authenticated users to inject arbitrary web script or HTML via a certain Comm... Read more
- EPSS Score: %0.34
- Published: Apr. 26, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2001-1271
Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames.... Read more
Affected Products : rar- EPSS Score: %0.14
- Published: Jul. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1270
Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.... Read more
Affected Products : pkzip- EPSS Score: %0.14
- Published: Jul. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0274
The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.... Read more
Affected Products : linux_trustees- EPSS Score: %0.78
- Published: Apr. 10, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1449
SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.... Read more
Affected Products : sunos- EPSS Score: %0.05
- Published: May. 19, 1997
- Modified: Apr. 03, 2025