Latest CVE Feed
-
2.1
LOWCVE-2004-1718
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.... Read more
Affected Products : integrity_protection_driver- Published: Aug. 17, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-2715
Cross-site scripting (XSS) vulnerability in the admin view in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a crafted field name.... Read more
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-1518
Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1627
Unknown vulnerability in Viewglob before 2.0.1, related to "a potential security issue with the Viewglob display and ssh X forwarding," has unknown impact.... Read more
Affected Products : viewglob- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1787
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Simple Corporate theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-3568
db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."... Read more
Affected Products : db2_content_manager- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2283
WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file.... Read more
Affected Products : webeoc- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2444
Trillian Pro 3.1 build 121, when checking Yahoo e-mail, stores the password in plaintext in a world readable file and does not delete the file after login, which allows local users to obtain sensitive information.... Read more
Affected Products : trillian_pro- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-4394
Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows local users to delete of arbitrary files via unknown vectors.... Read more
- Published: Aug. 17, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-5842
The keystore file in Unicore Client before 5.6 build 5, when running on Unix systems, has insecure default permissions, which allows local users to obtain sensitive information.... Read more
Affected Products : unicore_client- Published: Nov. 10, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-3706
The _sanitize_globals function in CodeIgniter 1.5.3 before 20070628 allows remote attackers to unset arbitrary global variables with unspecified impact, as demonstrated by a _SERVER cookie.... Read more
Affected Products : codeigniter- Published: Jul. 11, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-5600
Axalto Protiva 1.1, possibly only non-commercial versions, stores passwords in plaintext in files with insecure permissions, which allows local users to gain privileges by reading the passwords from (1) KeyTool\keytool.config or (2) webapps\protiva\WEB-IN... Read more
Affected Products : protiva- Published: Oct. 28, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-1376
The installation of Debian GNU/Linux 3.1r1 from the network install CD creates /var/log/debian-installer/cdebconf with world writable permissions, which allows local users to cause a denial of service (disk consumption).... Read more
Affected Products : debian_linux- Published: Mar. 24, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-3720
The process scheduler in the Linux kernel 2.4 performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that re... Read more
Affected Products : linux_kernel- Published: Jul. 12, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-1191
The Social Bookmarks (del.icio.us) plug-in 8F in Quicksilver writes usernames and passwords in plaintext to the /Library/Logs/Console/UID/Console.log file, which allows local users to obtain sensitive information by reading this file.... Read more
Affected Products : del.icio.us_module- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2002-0214
Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allows local users to decrypt network traffic by reading the ... Read more
Affected Products : intel_pro_wireless_2011b_lan_usb_device_driver- Published: May. 16, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1565
Point to Point Protocol daemon (pppd) in MacOS x 10.0 and 10.1 through 10.1.5 provides the username and password on the command line, which allows local users to obtain authentication information via the ps command.... Read more
Affected Products : mac_os_x- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6267
Citrix EdgeSight 4.2 and 4.5 for Presentation Server, EdgeSight 4.2 and 4.5 for Endpoints, and EdgeSight for NetScaler 1.0 and 1.1 do not properly store database credentials in configuration files, which allows local users to obtain sensitive information.... Read more
Affected Products : edgesight_for_endpoints edgesight_for_netscaler edgesight_for_presentation_server- Published: Dec. 07, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2001-0832
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the O... Read more
Affected Products : database_server- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0837
DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.... Read more
Affected Products : pc-to-phone- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025