Latest CVE Feed
-
2.1
LOWCVE-2013-0259
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.... Read more
- EPSS Score: %0.18
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-6108
HP Linux Imaging and Printing (HPLIP) before 3.13.2 uses world-writable permissions for /var/log/hp and /var/log/hp/tmp, which allows local users to delete log files via standard filesystem operations.... Read more
Affected Products : linux_imaging_and_printing_project- EPSS Score: %0.06
- Published: Feb. 15, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-5690
The Kerberos credential renewal feature in Sun Solaris 8, 9, and 10, and OpenSolaris build snv_01 through snv_104, allows local users to cause a denial of service (authentication failure) via unspecified vectors related to incorrect cache file permissions... Read more
- EPSS Score: %0.04
- Published: Dec. 19, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2011-2176
GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vectors.... Read more
Affected Products : networkmanager- EPSS Score: %0.05
- Published: Sep. 02, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-3866
lib/puppet/defaults.rb in Puppet 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, uses 0644 permissions for last_run_report.yaml, which allows local users to obtain sensitive configuration information by leveraging access to the puppet master serv... Read more
- EPSS Score: %0.05
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-2075
Cross-site scripting (XSS) vulnerability in the Contact Save module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the access site-wide contact form permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.34
- Published: Aug. 14, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-5586
The Services module 6.x-3.x before 6.x-3.3 and 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "access user profiles" permission to access arbitrary users' emails via vectors related to the "user index method" and "the path to... Read more
- EPSS Score: %0.25
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-0218
The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and th... Read more
- EPSS Score: %0.07
- Published: Feb. 05, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-0225
Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web scr... Read more
- EPSS Score: %0.34
- Published: Mar. 19, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-6119
Candlepin before 0.7.24, as used in Red Hat Subscription Asset Manager before 1.2.1, does not properly check manifest signatures, which allows local users to modify manifests.... Read more
- EPSS Score: %0.05
- Published: Apr. 02, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-4557
Cross-site scripting (XSS) vulnerability in the Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before 2009-07-15, a module for Drupal, allows remote authenticated u... Read more
- EPSS Score: %0.23
- Published: Jan. 04, 2010
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-0754
PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to o... Read more
- EPSS Score: %0.27
- Published: Mar. 03, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-4118
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (s... Read more
Affected Products : vpn_client- EPSS Score: %0.28
- Published: Dec. 01, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-3575
Unknown vulnerability in the Buffer Overflow Protection in McAfee VirusScan Enterprise 8.0.0 allows local users to cause a denial of service (unstable operation) via a long string in the (1) "Process name", (2) "Module name", or (3) "API name" fields.... Read more
Affected Products : virusscan- EPSS Score: %0.07
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-1679
The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1, when installing a configuration profile, can replace the password policy from Exchange ActiveSync with a weaker password policy, which allows physi... Read more
- EPSS Score: %0.07
- Published: Jun. 19, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-5061
Unspecified vulnerability in IBM Lotus Quickr 8.1 before 8.1.0.14 services for Lotus Domino, when Domino Native Authentication is enabled, might allow remote authenticated users to cause a denial of service (daemon crash) by going offline, aka SPR MLZG7UP... Read more
- EPSS Score: %0.57
- Published: Mar. 22, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-2207
The MobileMail component in Apple iPhone OS 3.0 and 3.0.1, and iPhone OS 3.0 for iPod touch, lists deleted e-mail messages in Spotlight search results, which might allow local users to obtain sensitive information by reading these messages.... Read more
Affected Products : iphone_os- EPSS Score: %0.06
- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-0504
WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.... Read more
Affected Products : websphere_application_server- EPSS Score: %0.05
- Published: Feb. 17, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-3669
Mercury Messenger, possibly 1.7.1.1 and other versions, when running on a multi-user Mac OS X platform, stores chat logs with world-readable permissions within the /Users directory, which allows local users to read the chat logs from other users.... Read more
Affected Products : mercury_messenger- EPSS Score: %0.05
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-0503
IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.... Read more
Affected Products : websphere_message_broker- EPSS Score: %0.06
- Published: Feb. 13, 2009
- Modified: Apr. 09, 2025