Latest CVE Feed
-
2.1
LOWCVE-1999-0782
KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.... Read more
- Published: Nov. 18, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0261
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.... Read more
Affected Products : aix- Published: Feb. 10, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1302
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a prob... Read more
Affected Products : windows_2000- Published: Jul. 18, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0790
clchkspuser and clpasswdremote in AIX expose an encrypted password in the cspoc.log file, which could allow local users to gain privileges.... Read more
Affected Products : aix- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0887
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack on temporary files, as demonstrated using log files.... Read more
Affected Products : openserver- Published: Oct. 04, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-5817
prl_dhcpd in Parallels Desktop for Mac Build 1940 uses insecure permissions (0666) for /Library/Parallels/.dhcpd_configuration, which allows local users to modify DHCP configuration.... Read more
Affected Products : parallels_desktop- Published: Nov. 08, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2001-1122
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.... Read more
Affected Products : windows_nt- Published: Aug. 03, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3331
viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : mgdiff_patch_viewer- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-2201
The screensharing feature in the Admin application in Apple Xsan before 2.2 places a cleartext username and password in a URL within an error dialog, which allows physically proximate attackers to obtain credentials by reading this dialog.... Read more
Affected Products : xsan- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2011-2263
Unspecified vulnerability in Sun Integrated Lights Out Manager in Oracle SysFW 8.0.3.b or earlier for various Oracle SPARC T3, SPARC Netra T3, Sun Blade, and Sun Fire servers allows local users to affect confidentiality via unknown vectors.... Read more
Affected Products : sysfw netra_sparc_t3-1 sparc_t3-1 sparc_t3-1b sparc_t3-3 sparc_t3-4 sun_blade_x6250 sun_blade_x6270 sun_blade_x6270_m2 sun_blade_x6275 +13 more products- Published: Jul. 20, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-0619
Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.... Read more
Affected Products : einstein- Published: Feb. 28, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-6434
Linux kernel 2.6.23 allows local users to create low pages in virtual userspace memory and bypass mmap_min_addr protection via a crafted executable file that calls the do_brk function.... Read more
Affected Products : linux_kernel- Published: Dec. 18, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2003-1077
Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).... Read more
Affected Products : solaris- Published: Mar. 05, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2025-2236
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability could reveal sensitive information while managing and configuring of the externa... Read more
Affected Products :- Published: May. 27, 2025
- Modified: May. 28, 2025
- Vuln Type: Information Disclosure
-
2.1
LOWCVE-2025-46729
julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web their DVD collections maintained with Invelos's DVDProfiler software. Starting in v_20230807 and prior to v_20250511, cross-site scripting... Read more
Affected Products :- Published: May. 12, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
2.1
LOWCVE-2011-0515
KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (crash) via a crafted request that is not properly handled by the KiFastCallEntry hook.... Read more
- Published: Jan. 20, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2023-52275
Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3d/.privatealbum/.encryptfiles and guessing the correct image file extension.... Read more
- Published: Dec. 31, 2023
- Modified: Nov. 21, 2024
-
2.1
LOWCVE-2024-50349
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When Git asks for credentials via a terminal prompt (i.e. without using any credential h... Read more
Affected Products : git- Published: Jan. 14, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Information Disclosure
-
2.1
LOWCVE-2011-0524
Multiple buffer overflows in the NMEA parser (nmea-gen.c) in gypsy 0.8 allow local users to cause a denial of service (crash) via unspecified vectors related to the sprintf function.... Read more
Affected Products : gypsy- Published: Aug. 13, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2024-50398
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modif... Read more
- Published: Nov. 22, 2024
- Modified: Nov. 22, 2024