Latest CVE Feed
-
2.1
LOWCVE-2005-3620
The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to ... Read more
Affected Products : esx- EPSS Score: %0.11
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0577
Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service.... Read more
Affected Products : hp-ux- EPSS Score: %0.10
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-5488
Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "administer mailchimp" permission to inject arbitrary web script or HTML via un... Read more
Affected Products : mailchimp- EPSS Score: %0.21
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2002-2165
The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.... Read more
Affected Products : imho_webmail- EPSS Score: %0.38
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1144
Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resulting "/" file system is higher than normal, which allows attackers to determine that they are in a chroot environment.... Read more
Affected Products : mantrap- EPSS Score: %0.60
- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1550
CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.... Read more
- EPSS Score: %0.18
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3159
pipe_master in Sun ONE/iPlanet Messaging Server 5.2 HotFix 1.16 (built May 14 2003) allows local users to read portions of restricted files via a symlink attack on msg.conf in a directory identified by the CONFIGROOT environment variable, which returns th... Read more
- EPSS Score: %0.08
- Published: Jun. 22, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0473
The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.... Read more
Affected Products : rsync- EPSS Score: %0.10
- Published: Apr. 07, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1748
NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.... Read more
Affected Products : regmon- EPSS Score: %0.42
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0355
netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.... Read more
Affected Products : irix- EPSS Score: %0.16
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1667
The virtual memory management system in FreeBSD 4.5-RELEASE and earlier does not properly check the existence of a VM object during page invalidation, which allows local users to cause a denial of service (crash) by calling msync on an unaccessed memory m... Read more
Affected Products : freebsd- EPSS Score: %0.06
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0377
Gaim 0.57 stores sensitive information in world-readable and group-writable files in the /tmp directory, which allows local users to access MSN web email accounts of other users who run Gaim by reading authentication information from the files.... Read more
Affected Products : gaim- EPSS Score: %0.12
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-4931
HP System Management Homepage (SMH) for Windows, when used in conjunction with HP Version Control Agent or Version Control Repository Manager, leaves old OpenSSL software active after an OpenSSL update, which has unknown impact and attack vectors, probabl... Read more
Affected Products : system_management_homepage- EPSS Score: %0.17
- Published: Sep. 18, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-1876
Microsoft Exchange 2000 allows remote authenticated attackers to cause a denial of service via a large number of rapid requests, which consumes all of the licenses that are granted to Exchange by IIS.... Read more
Affected Products : exchange_server- EPSS Score: %0.82
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1502
Symbolic link vulnerability in xbreaky before 0.5.5 allows local users to overwrite arbitrary files via a symlink from the user's .breakyhighscores file to the target file.... Read more
Affected Products : xbreaky- EPSS Score: %0.18
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-0941
EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key... Read more
- EPSS Score: %0.07
- Published: May. 22, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-0234
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consume... Read more
Affected Products : netscreen_screenos- EPSS Score: %0.08
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2309
Directory traversal vulnerability in Crob FTP Server 3.5.1 allows local users to browse outside the FTP root via multiple ../ (dot dot slash) in the DIR command.... Read more
Affected Products : crob_ftp_server- EPSS Score: %0.18
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-3785
Symantec pcAnywhere 12.5 obfuscates the passwords in a GUI textbox with asterisks but does not encrypt them in the associated .cif (aka caller or CallerID) file, which allows local users to obtain the passwords from the window using tools such as Nirsoft ... Read more
Affected Products : pcanywhere- EPSS Score: %0.08
- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-3724
The process scheduler in the Microsoft Windows XP kernel does not make use of the process statistics kept by the kernel, performs scheduling based on CPU billing gathered from periodic process sampling ticks, and gives preference to "interactive" processe... Read more
Affected Products : windows_xp- EPSS Score: %0.26
- Published: Jul. 12, 2007
- Modified: Apr. 09, 2025