Latest CVE Feed
-
2.1
LOWCVE-2001-1273
The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).... Read more
Affected Products : linux_kernel- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1378
fetchmailconf in fetchmail before 5.7.4 allows local users to overwrite files of other users via a symlink attack on temporary files.... Read more
Affected Products : fetchmail- Published: Sep. 06, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-6375
The debug-logging (aka debug cns) feature in Cisco Networking Services (CNS) for IOS 15.2(2)E3 allows local users to obtain sensitive information by reading an unspecified file, aka Bug ID CSCux18010.... Read more
Affected Products : ios- Published: Nov. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2002-0790
clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.... Read more
Affected Products : aix- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2766
Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain th... Read more
Affected Products : norton_antivirus- Published: Sep. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-5204
Cross-site scripting (XSS) vulnerability in action_admin/member.php in Invision Power Board (IPB) 2.1.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML via a reference to a script in the avatar setting, which can be le... Read more
Affected Products : invision_power_board- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2004-2321
BEA WebLogic Server and Express 8.1 SP1 and earlier allows local users in the Operator role to obtain administrator passwords via MBean attributes, including (1) ServerStartMBean.Password and (2) NodeManagerMBean.CertificatePassword.... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2008-0216
The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty fr... Read more
Affected Products : freebsd- Published: Jan. 16, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-1996
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.... Read more
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-3223
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.0.1 allows remote authenticated users to affect confidentiality, related to BASE.... Read more
Affected Products : financial_services_software- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-2466
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-0976
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained fr... Read more
Affected Products : silverstripe- Published: Feb. 02, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-1927
Aquonics File Manager 1.5 allows users with edit privileges to modify user accounts by editing the userlist.cgi file.... Read more
Affected Products : aquonics_file_manager- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-5100
Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, which might allow physically proximate attackers to obtain the password.... Read more
Affected Products : bi_server- Published: Sep. 13, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-6150
The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that... Read more
Affected Products : freebsd- Published: Nov. 30, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2001-0741
Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.... Read more
Affected Products : hsrp- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-3929
Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject arbitrary web script or HTML via the handler parameter.... Read more
Affected Products : cms_made_simple- Published: Dec. 09, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-2419
Keene Digital Media Server 1.0.2 allows local users to obtain usernames and passwords by reading the dmscore.db file on the local system.... Read more
Affected Products : digital_media_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-1355
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.... Read more
Affected Products : simatic_step_7- Published: Feb. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2007-1194
Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows... Read more
Affected Products : norman_sandbox_analyzer- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025