Latest CVE Feed
-
2.1
LOWCVE-2005-0904
Remote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut down the system by executing TSShutdn.exe.... Read more
Affected Products : windows_xp- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0136
The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.... Read more
Affected Products : linux_kernel- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0711
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users with CREATE TEMPORARY TABLE privileges to overwrite arbitrary files via a symlink attack.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-4352
Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.... Read more
Affected Products : d-bus- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4217
The OSAL_Crypt_SetEncryptedPassword function in InfraStack/OSDependent/Linux/OSAL/Services/wimax_osal_crypt_services.c in the OSAL crypt module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices logs a cleart... Read more
Affected Products : wimax_network_service- Published: Aug. 25, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-0245
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows remote authenticated users with the "access printer-friendl... Read more
Affected Products : drupal- Published: Jul. 16, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4064
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTH... Read more
- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2001-0907
Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link.... Read more
Affected Products : linux_kernel- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-0259
Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.... Read more
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-0266
manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the ... Read more
- Published: Mar. 08, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2539
Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of temporary files.... Read more
- Published: Aug. 02, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-1831
Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.... Read more
Affected Products : passenger- Published: Feb. 19, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-0370
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-2389
hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might allow local users to obtain sensitive information such as credentials.... Read more
Affected Products : hostapd- Published: Jun. 21, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2013
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.... Read more
Affected Products : python-keystoneclient- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4216
The Trace_OpenLogFile function in InfraStack/OSDependent/Linux/InfraStackModules/TraceModule/TraceModule.c in the Trace module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses world-writable permission... Read more
Affected Products : wimax_network_service- Published: Aug. 25, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2148
The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation on th... Read more
Affected Products : linux_kernel- Published: Jun. 07, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-2033
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via ... Read more
- Published: Apr. 10, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-9584
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memo... Read more
- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-4274
Cross-site scripting (XSS) vulnerability in the password_policy_admin_view function in password_policy.admin.inc in the Password Policy module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Adminis... Read more
- Published: Aug. 28, 2013
- Modified: Apr. 11, 2025