Latest CVE Feed
-
1.9
LOWCVE-2011-1310
The Administrative Scripting Tools component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.35 and 7.x before 7.0.0.15, when tracing is enabled, places wsadmin command parameters into the (1) wsadmin.traceout and (2) trace.log files, which... Read more
Affected Products : websphere_application_server- EPSS Score: %0.05
- Published: Mar. 08, 2011
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2007-0473
The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.... Read more
Affected Products : smb4k- EPSS Score: %0.06
- Published: Feb. 03, 2007
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2008-2329
Directory Services in Apple Mac OS X 10.5 through 10.5.4, when Active Directory is used, allows attackers to enumerate user names via wildcard characters in the Login Window.... Read more
- EPSS Score: %0.09
- Published: Sep. 16, 2008
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2010-0826
The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack involving a setgid or setuid appli... Read more
Affected Products : libnss-db- EPSS Score: %0.07
- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-2898
drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted devi... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2013-2636
net/bridge/br_mdb.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Mar. 22, 2013
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2012-3432
The handle_mmio function in arch/x86/hvm/io.c in the MMIO operations emulator for Xen 3.3 and 4.x, when running an HVM guest, does not properly reset certain state information between emulation cycles, which allows local guest OS users to cause a denial o... Read more
Affected Products : xen- EPSS Score: %1.42
- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
1.9
LOWCVE-2009-0434
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain ... Read more
Affected Products : websphere_application_server- EPSS Score: %0.06
- Published: Feb. 10, 2009
- Modified: Apr. 09, 2025
-
1.9
LOWCVE-2009-2012
Unspecified vulnerability in idmap in Sun OpenSolaris snv_88 through snv_110, when a CIFS server is enabled, allows local users to cause a denial of service (idpmapd daemon crash and idmapd outage) via unknown vectors.... Read more
Affected Products : opensolaris- EPSS Score: %0.06
- Published: Jun. 09, 2009
- Modified: Apr. 09, 2025
-
1.8
LOWCVE-2007-2999
Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers t... Read more
- EPSS Score: %1.25
- Published: Jun. 04, 2007
- Modified: Apr. 09, 2025
-
1.8
LOWCVE-2013-0179
The process_bin_delete function in memcached.c in memcached 1.4.4 and other versions before 1.4.17, when running in verbose mode, allows remote attackers to cause a denial of service (segmentation fault) via a request to delete a key, which does not accou... Read more
Affected Products : memcached- EPSS Score: %1.34
- Published: Jan. 13, 2014
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2012-2425
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allow remote attackers to cause a denial of service (application crash) v... Read more
- EPSS Score: %0.21
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2024-36119
Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matchin... Read more
Affected Products : statamic- Published: May. 30, 2024
- Modified: Nov. 21, 2024
-
1.8
LOWCVE-2012-2424
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allow remote attackers to cause a denial of service (NULL pointer derefer... Read more
- EPSS Score: %0.18
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2015-1798
The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MA... Read more
Affected Products : ntp- EPSS Score: %0.68
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2024-5532
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent. The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
1.8
LOWCVE-2014-4812
The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, which allows remote attackers to obtain sensitive information by connecting to this port.... Read more
Affected Products : security_appscan_source- EPSS Score: %0.11
- Published: Oct. 26, 2014
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2025-32382
Metabase is an open source Business Intelligence and Embedded Analytics tool. When admins change Snowflake connection details in Metabase (either updating a password or changing password to private key or vice versa), Metabase would not always purge older... Read more
Affected Products : metabase- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2015-0875
The Ogaki Kyoritsu Bank Smartphone Passbook application 1.0.0 for Android creates a log file containing input data from the user, which allows attackers to obtain sensitive information by reading a file.... Read more
- EPSS Score: %0.09
- Published: Feb. 15, 2015
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2012-2420
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to obtain sensitive information via a URI wi... Read more
- EPSS Score: %0.16
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025