Latest CVE Feed
-
2.1
LOWCVE-2011-4922
cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or other representation of memory contents.... Read more
Affected Products : pidgin- Published: Aug. 08, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-2104
sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.... Read more
Affected Products : sysreport- Published: Oct. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0512
PADL MigrationTools 46 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the temporary files, which are not properly created by (1) migrate_all_online.sh, (2) migrate_all_offline.sh, (3) migr... Read more
Affected Products : migrationtools- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3137
The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.... Read more
Affected Products : cfengine- Published: Oct. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-0207
ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.... Read more
Affected Products : gs-common- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2071
Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment. NOTE: some original raw sources combined this issue wit... Read more
- Published: Apr. 27, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2110
Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only intended to be allowed by the guest-root.... Read more
Affected Products : vserver- Published: May. 01, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2462
Kayako liveResponse 2.x, when logging in a user, records the password in plaintext in the URL, which allows local users and possibly remote attackers to gain privileges.... Read more
Affected Products : liveresponse- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-4899
WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials by reading an unspecified file.... Read more
Affected Products : kingview- Published: Oct. 10, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2003-1295
Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password."... Read more
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-4615
EMC Smarts Network Configuration Manager (NCM) before 9.1 uses a hardcoded encryption key for the storage of credentials, which allows local users to obtain sensitive information via unspecified vectors.... Read more
- Published: Nov. 27, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-5038
Eucalyptus 3.0.0 through 4.0.1, when the log level is set to DEBUG or lower, logs user and system passwords, which allows local users to obtain sensitive information by reading the cloud log files.... Read more
Affected Products : eucalyptus- Published: Nov. 07, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2016-3888
internal/telephony/SMSDispatcher.java in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism, ... Read more
Affected Products : android- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-4412
Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to direc... Read more
Affected Products : program_neighborhood_client- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-2299
The Ubercart module 6.x-2.x before 6.x-2.8 and 7.x-3.x before 7.x-3.1 for Drupal stores passwords for new customers in plaintext during checkout, which allows local users to obtain sensitive information by reading from the database.... Read more
- Published: Aug. 14, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-5084
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically proximate attackers to obtain sensitive information via unspecified vectors.... Read more
- Published: Aug. 03, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-9252
Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain sensitive information by reading database entries, aka ZEN-15416.... Read more
Affected Products : zenoss_core- Published: Dec. 15, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-1584
Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.... Read more
- Published: May. 19, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-4589
Login.aspx in the Portal in McAfee Enterprise Mobility Manager (EMM) before 10.0 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.... Read more
Affected Products : enterprise_mobility_manager- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2023-52275
Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3d/.privatealbum/.encryptfiles and guessing the correct image file extension.... Read more
- Published: Dec. 31, 2023
- Modified: Nov. 21, 2024