Latest CVE Feed
-
2.1
LOWCVE-2007-6363
IBM Tivoli Netcool Security Manager 1.3.0 before Interim Fix 1, when using Active Directory (AD) LDAP authentication, allows remote attackers to obtain login access via unspecified vectors without entering a password.... Read more
Affected Products : tivoli_netcool_security_manager- EPSS Score: %0.17
- Published: Dec. 15, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2012-1060
Multiple cross-site scripting (XSS) vulnerabilities in revisioning_theme.inc in the Taxonomy module in the Revisioning module 6.x-3.13 and other versions before 6.x-3.14 for Drupal allow remote authenticated users with certain privileges to inject arbitra... Read more
- EPSS Score: %0.34
- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-5488
Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "administer mailchimp" permission to inject arbitrary web script or HTML via un... Read more
Affected Products : mailchimp- EPSS Score: %0.21
- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-1780
Cross-site scripting (XSS) vulnerability in the Best Responsive Theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.... Read more
- EPSS Score: %0.35
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-0124
Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.... Read more
Affected Products : employee_timeclock_software- EPSS Score: %0.06
- Published: Mar. 15, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-7215
The Intel Core 2 Extreme processor X6800 and Core 2 Duo desktop processor E6000 and E4000 incorrectly set the memory page Access (A) bit for a page in certain circumstances involving proximity of the code segment limit to the end of a code page, which has... Read more
- EPSS Score: %0.08
- Published: Jul. 03, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-3952
The fill_pipeinfo function in bsd/kern/sys_pipe.c in the XNU kernel in Apple Mac OS X 10.8.x allows local users to defeat the KASLR protection mechanism via the PROC_PIDFDPIPEINFO option to the proc_info system call for a kernel pipe handle.... Read more
- EPSS Score: %0.13
- Published: Jun. 05, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-0941
EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key... Read more
- EPSS Score: %0.07
- Published: May. 22, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-0441
IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) after a reconfig action; which allows local users to obtain sensitive informati... Read more
Affected Products : tivoli_business_service_manager- EPSS Score: %0.06
- Published: Jan. 25, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-1092
Unspecified vulnerability in the pagedata subsystem of the process file system (/proc) in Solaris 8 through 10 allows local users to cause a denial of service (system hang or panic) via unknown attack vectors that cause cause the kmem_oversize arena to al... Read more
- EPSS Score: %0.07
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-3615
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.... Read more
- EPSS Score: %0.09
- Published: Nov. 01, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-1348
Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mounting... Read more
Affected Products : iphone_os- EPSS Score: %0.08
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2008-0740
IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this fil... Read more
Affected Products : websphere_application_server- EPSS Score: %0.06
- Published: Feb. 13, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-1451
The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, whi... Read more
- EPSS Score: %0.10
- Published: May. 07, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-5373
ldapscripts 1.4 and 1.7 sends a password as a command line argument when calling some LDAP programs, which might allow local users to read the password by listing the process and its arguments, as demonstrated by a call to ldappasswd in the _changepasswor... Read more
Affected Products : ldapscripts- EPSS Score: %0.07
- Published: Oct. 11, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-0119
Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."... Read more
- EPSS Score: %0.06
- Published: Feb. 25, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-0010
The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.... Read more
Affected Products : linux_kernel- EPSS Score: %0.24
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-0754
PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to o... Read more
- EPSS Score: %0.27
- Published: Mar. 03, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2008-3528
The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate... Read more
Affected Products : linux_kernel- EPSS Score: %0.35
- Published: Sep. 27, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-0547
client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a craft... Read more
Affected Products : samba- EPSS Score: %1.29
- Published: Feb. 04, 2010
- Modified: Apr. 11, 2025