Latest CVE Feed
-
2.1
LOWCVE-2006-0077
Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.... Read more
Affected Products : file_extattr- Published: Jan. 04, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0694
Denial of service in AIX ptrace system call allows local users to crash the system.... Read more
Affected Products : aix- Published: Aug. 11, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2011-5189
Cross-site scripting (XSS) vulnerability in the Webform Validation module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with permissions to "update Webform nodes" to inject arbitrary web script or HTML via ... Read more
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-1927
Aquonics File Manager 1.5 allows users with edit privileges to modify user accounts by editing the userlist.cgi file.... Read more
Affected Products : aquonics_file_manager- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6150
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that... Read more
Affected Products : freebsd- Published: Nov. 30, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2005-4273
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.... Read more
Affected Products : aix- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1271
Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.... Read more
Affected Products : dreamweaver- Published: Jun. 11, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4755
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier (1) stores the private key passphrase (CustomTrustKeyStorePassPhrase) in cleartext in nodemanager.config; or, during domain creation with the Configuration Wizard, renders an SSL private key pas... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-3800
XBMC 13.0 uses world-readable permissions for .xbmc/userdata/sources.xml, which allows local users to obtain user names and passwords by reading this file.... Read more
Affected Products : xbmc- Published: Aug. 07, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-3272
EMC Replication Manager (RM) before 5.4.4 places encoded passwords in application log files, which makes it easier for local users to obtain sensitive information by reading a file and conducting an unspecified decoding attack.... Read more
Affected Products : replication_manager- Published: Jul. 08, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-5429
The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it ... Read more
Affected Products : tivoli_federated_identity_manager- Published: Jan. 21, 2014
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-6754
Cross-site scripting (XSS) vulnerability in the administration interface in the Path Breadcrumbs module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "Administer Path Breadcrumbs" permission to inject arbitrary web script or... Read more
Affected Products : path_breadcrumbs- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2009-2201
The screensharing feature in the Admin application in Apple Xsan before 2.2 places a cleartext username and password in a URL within an error dialog, which allows physically proximate attackers to obtain credentials by reading this dialog.... Read more
Affected Products : xsan- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-1951
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX001, and 7.6.0 before 7.6.0.0 IFIX005 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by levera... Read more
Affected Products : maximo_asset_management- Published: Jul. 01, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2008-1738
Rising Antivirus 2008 before 20.38.20 allows local users to cause a denial of service (system crash) via an invalid pointer to the _CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descriptor Table (SSDT) function.... Read more
Affected Products : rising_antivirus- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2009-5008
Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verification, which allows local users to bypass intended policy restrictions via a modified executable file.... Read more
Affected Products : secure_desktop- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2001-1378
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.... Read more
Affected Products : fetchmail- Published: Sep. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-2612
Unspecified vulnerability in the HP OpenVMS Auditing feature in OpenVMS ALPHA 7.3-2, 8.2, and 8.3; and OpenVMS for Integrity Servers 8.3 AND 8.3-1H1; allows local users to obtain sensitive information via unknown vectors.... Read more
- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-2586
Mentor ADSL-FR4II router running firmware 2.00.0111 stores the web administration password in cleartext in the backup configuration file, which allows local users to obtain sensitive information.... Read more
Affected Products : adslfr4ii- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2023-22473
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the... Read more
- Published: Jan. 09, 2023
- Modified: Nov. 21, 2024