Latest CVE Feed
-
2.1
LOWCVE-2015-1951
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by levera... Read more
Affected Products : maximo_asset_management- Published: Jul. 01, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2024-37046
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to read the contents of unexpected files and expose sensit... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024
-
2.1
LOWCVE-2025-3154
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.... Read more
Affected Products : xpdf- Published: Apr. 02, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Memory Corruption
-
2.1
LOWCVE-2012-6110
bcron-exec in bcron before 0.10 does not close file descriptors associated with temporary files when running a cron job, which allows local users to modify job files and send spam messages by accessing an open file descriptor.... Read more
Affected Products : bcron_exec- Published: Sep. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-2334
The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be... Read more
- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-3273
EMC RSA Authentication Manager 8.0 before P2 and 7.1 before SP4 P26, as used in Appliance 3.0, does not omit the cleartext administrative password from trace logging in custom SDK applications, which allows local users to obtain sensitive information by r... Read more
- Published: Jul. 08, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-1903
Buffer overflow in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to execute arbitrary code via a long CREATE command.... Read more
Affected Products : spa-pro_mail_atsolomon- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1364
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4788
resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, allows local users to bypass access control rules for USB devices via "alternate syntax for specifying USB devices."... Read more
Affected Products : suse_linux- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0008
FTPPro allows local users to read sensitive information, which is stored in plain text.... Read more
Affected Products : ftppro- Published: Dec. 26, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-1234
The paratrooper-newrelic gem 1.0.1 for Ruby allows local users to obtain the X-Api-Key value by listing the curl process.... Read more
Affected Products : paratrooper-newrelic- Published: Jan. 10, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-2327
Unspecified vulnerability in the Oracle Communications Unified component in Oracle Sun Products Suite 7.0 allows local users to affect confidentiality via unknown vectors related to Delegated Administrator.... Read more
Affected Products : sun_products_suite- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2000-0334
The Allaire Spectra container editor preview tool does not properly enforce object security, which allows an attacker to conduct unauthorized activities via an object-method that is added to the container object with a publishing rule.... Read more
Affected Products : spectra- Published: Apr. 24, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1146
Recourse ManTrap 1.6 allows attackers to cause a denial of service via a sequence of commands that navigate into and out of the /proc/self directory and executing various commands such as ls or pwd.... Read more
Affected Products : mantrap- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2180
gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.... Read more
Affected Products : gnats- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-1233
The paratrooper-pingdom gem 1.0.0 for Ruby allows local users to obtain the App-Key, username, and password values by listing the curl process.... Read more
Affected Products : paratrooper-pingdom- Published: Jan. 10, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2003-0175
SGI IRIX before 6.5.21 allows local users to cause a denial of service (kernel panic) via a certain call to the PIOCSWATCH ioctl.... Read more
Affected Products : irix- Published: Feb. 03, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0547
Memory leak in the proxy service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows local attackers to cause a denial of service (resource exhaustion).... Read more
Affected Products : isa_server- Published: Sep. 20, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-8733
Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.... Read more
Affected Products : cloudera_manager- Published: Feb. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-4862
The Host Connect emulator in IBM Rational Developer for System z 7.1 through 8.5.1 does not properly store the SSL certificate password, which allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : rational_developer_for_system_z- Published: Dec. 05, 2012
- Modified: Apr. 11, 2025