Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 2.1

    LOW
    CVE-1999-0133

    fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.... Read more

    Affected Products : framemaker
    • Published: Aug. 14, 1996
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-0838

    IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 stores cleartext passwords in the (1) CMS_DBPASS, (2) CMSM_DBPASS, and (3) RPT_DBPASS fields in /etc/neusecure.conf, and in (4) /opt/NeuSecure/bin/ns_archiver.log, which allows local users to gain privileges.... Read more

    Affected Products : netcool_neusecure
    • Published: Feb. 22, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0451

    Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.... Read more

    Affected Products : linux_kernel
    • Published: Jan. 19, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0464

    Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.... Read more

    Affected Products : tripwire
    • Published: Jan. 04, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0480

    Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack.... Read more

    Affected Products : midnight_commander
    • Published: Apr. 01, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0460

    Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.... Read more

    Affected Products : linux_kernel
    • Published: Feb. 19, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-0431

    Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 SP5 allows untrusted applications to obtain the server's SSL identity via unknown attack vectors.... Read more

    Affected Products : weblogic_server
    • Published: Jan. 25, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2008-2747

    No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Userna... Read more

    Affected Products : windows dynamic_update_client
    • Published: Jun. 18, 2008
    • Modified: Apr. 09, 2025
  • 2.1

    LOW
    CVE-2006-0427

    Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 9.0 and 8.1 through SP5 allows malicious EJBs or servlet applications to decrypt system passwords, possibly by accessing functionality that should have been restricted.... Read more

    Affected Products : weblogic_server
    • Published: Jan. 25, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-3276

    The sys_get_thread_area function in process.c in Linux 2.6 before 2.6.12.4 and 2.6.13 does not clear a data structure before copying it to userspace, which might allow a user process to obtain sensitive information.... Read more

    Affected Products : linux_kernel enterprise_linux
    • Published: Oct. 21, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-0967

    NCP Network Communication Secure Client 8.11 Build 146, and possibly other versions, allows local users to cause a denial of service (memory usage and cpu utilization) via a flood of arbitrary UDP datagrams to ports 0 to 65000. NOTE: this issue was report... Read more

    Affected Products : secure_client
    • Published: Mar. 02, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2008-1970

    muCommander before 0.8.2 stores credentials.xml with insecure permissions, which allows local users to obtain credentials.... Read more

    Affected Products : mucommander
    • Published: Apr. 27, 2008
    • Modified: Apr. 09, 2025
  • 2.1

    LOW
    CVE-1999-0473

    The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.... Read more

    Affected Products : rsync
    • Published: Apr. 07, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0367

    NetBSD netstat command allows local users to access kernel memory.... Read more

    Affected Products : netbsd
    • Published: Feb. 09, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0442

    Solaris ff.core allows local users to modify files.... Read more

    Affected Products : solaris sunos
    • Published: Jan. 07, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0595

    A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.... Read more

    Affected Products : windows_2000 windows_nt
    • Published: Jan. 20, 2000
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2006-1092

    Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to al... Read more

    Affected Products : solaris sunos
    • Published: Mar. 09, 2006
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-1999-0372

    The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted.... Read more

    Affected Products : windows_2000 windows_nt backoffice
    • Published: Feb. 12, 1999
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2008-3067

    sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits.... Read more

    Affected Products : opensuse opensuse
    • Published: Jul. 07, 2008
    • Modified: Apr. 09, 2025
  • 2.1

    LOW
    CVE-2006-0917

    Melange Chat Server (aka M-Chat), when accessed via a web browser, automatically sends cookies and other sensitive information for a server to any port specified in the associated link, which allows local users on that server to read the cookies from HTTP... Read more

    Affected Products : melange_chat_system
    • Published: Feb. 28, 2006
    • Modified: Apr. 03, 2025
Showing 20 of 293260 Results