Latest CVE Feed
-
2.1
LOWCVE-2006-2103
SQL injection vulnerability in MyBB (MyBulletinBoard) 1.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the (1) query string ($querystring variable) in (a) admin/adminlogs.php, which is not properly handled by adminfun... Read more
Affected Products : mybulletinboard- EPSS Score: %0.35
- Published: Apr. 29, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3069
xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.... Read more
Affected Products : hylafax- EPSS Score: %0.07
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3088
fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.... Read more
Affected Products : fetchmail- EPSS Score: %0.09
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2612
Novell Client for Windows 4.8 and 4.9 does not restrict access to the clipboard contents while a machine is locked, which allows users with physical access to read the current clipboard contents by pasting them into the "User Name" field on the login prom... Read more
Affected Products : client- EPSS Score: %0.08
- Published: May. 26, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1997
Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknown attack vectors.... Read more
Affected Products : pylon_anywhere- EPSS Score: %0.08
- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1393
Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).... Read more
- EPSS Score: %0.07
- Published: Apr. 17, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-1420
MySQL 5.x before 5.0.36 allows local users to cause a denial of service (database crash) by performing information_schema table subselects and using ORDER BY to sort a single-row result, which prevents certain structure elements from being initialized and... Read more
- EPSS Score: %0.15
- Published: Mar. 12, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2006-1439
NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events.... Read more
Affected Products : mac_os_x- EPSS Score: %0.08
- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4536
Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file.... Read more
Affected Products : libmail-audit-perl- EPSS Score: %0.07
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2563
The cURL library (libcurl) in PHP 4.4.2 and 5.1.4 allows attackers to bypass safe mode and read files via a file:// request containing null characters.... Read more
Affected Products : php- EPSS Score: %0.24
- Published: May. 29, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0416
sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.... Read more
- EPSS Score: %0.09
- Published: Jun. 27, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2025-3840
An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer component which is deployed for installation purposes in a customer network. This EOL component was deprecated in September 2023 with end... Read more
Affected Products :- Published: Apr. 21, 2025
- Modified: Apr. 21, 2025
- Vuln Type: Cross-Site Scripting
-
2.1
LOWCVE-2020-14541
Vulnerability in the Hyperion Financial Close Management product of Oracle Hyperion (component: Close Manager). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via ... Read more
Affected Products : hyperion_financial_close_management- EPSS Score: %0.22
- Published: Jul. 15, 2020
- Modified: Nov. 21, 2024
-
2.1
LOWCVE-2023-52275
Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3d/.privatealbum/.encryptfiles and guessing the correct image file extension.... Read more
- EPSS Score: %0.06
- Published: Dec. 31, 2023
- Modified: Nov. 21, 2024
-
2.1
LOWCVE-2006-0077
Off-by-one error in the getfattr function in File::ExtAttr before 0.03 allows attackers to trigger a buffer overflow via unspecified attack vectors.... Read more
Affected Products : file_extattr- EPSS Score: %0.09
- Published: Jan. 04, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0458
The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.... Read more
Affected Products : imp- EPSS Score: %0.12
- Published: Apr. 22, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-1527
easyNews 1.5 and earlier stores administration passwords in cleartext in settings.php, which allows local users to obtain the passwords and gain access.... Read more
Affected Products : easynews- EPSS Score: %0.06
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1197
POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for ot... Read more
Affected Products : imap- EPSS Score: %0.08
- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1285
Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Dec. 27, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-1194
Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows... Read more
Affected Products : norman_sandbox_analyzer- EPSS Score: %0.07
- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025