Latest CVE Feed
-
2.1
LOWCVE-2014-0199
The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allows local users to obtain sensitive information by reading... Read more
Affected Products : rhevm-reports- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6956
Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4 before 7.4r6, and 8.0 before 8.0r1, when web rewrite is... Read more
Affected Products : ive_os- Published: Dec. 13, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-5066
The SibRaRecoverableSiXaResource class in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 does not properly handle a Service Integration Bus (SIB) dump operation involving the First Failure Data Capture (FFDC)... Read more
Affected Products : websphere_application_server- Published: Jan. 15, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0711
The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V... Read more
- Published: Mar. 01, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-100039
mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. NOTE: some of these details are obtained from third pa... Read more
Affected Products : malwarebytes_anti-exploit- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-7064
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML vi... Read more
Affected Products : eu_cookie_compliance- Published: Apr. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-0201
ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users to obtain sensitive information by reading the files.... Read more
Affected Products : rhevm-reports- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-1999-1010
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.... Read more
Affected Products : openssh- Published: Dec. 14, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0893
userOsa in SCO OpenServer allows local users to corrupt files via a symlink attack.... Read more
Affected Products : openserver- Published: Oct. 11, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0139
Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.... Read more
Affected Products : internet_anywhere_mail_server- Published: Dec. 03, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0227
The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets.... Read more
- Published: Mar. 23, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-2083
The Novell Netware client running on Windows 95 allows local users to bypass the login and open arbitrary files via the "What is this?" help feature, which can be launched from the Novell Netware login screen.... Read more
Affected Products : netware- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1731
The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that are type USRPRF.... Read more
Affected Products : os_400- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0871
xinetd 2.3.4 leaks file descriptors for the signal pipe to services that are launched by xinetd, which could allow those services to cause a denial of service via the pipe.... Read more
- Published: Sep. 05, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0184
Linux printtool sets the permissions of printer configuration files to be world-readable, which allows local attackers to obtain printer share passwords.... Read more
- Published: Mar. 09, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0795
The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files.... Read more
Affected Products : freebsd- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1786
SGI IRIX 6.5 through 6.5.14 applies a umask of 022 to root core dumps, which allows local users to read the core dumps and possibly obtain sensitive information.... Read more
Affected Products : irix- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0679
The CVS 1.10.8 client trusts pathnames that are provided by the CVS server, which allows the server to force the client to create arbitrary files.... Read more
Affected Products : cvs- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0584
IMAP server in Alt-N Technologies MDaemon 3.5.6 allows a local user to cause a denial of service (hang) via long (1) SELECT or (2) EXAMINE commands.... Read more
Affected Products : mdaemon- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0124
surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions.... Read more
Affected Products : superscout- Published: Feb. 03, 2000
- Modified: Apr. 03, 2025