Latest CVE Feed
-
2.1
LOWCVE-2002-0121
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.... Read more
Affected Products : php- Published: Mar. 25, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-6744
phpProfiles before 2.1.1 does not have an index.php or other index file in the (1) image_data, (2) graphics/comm, or (3) users read/write directories, which might allow remote attackers to list directory contents or have other unknown impacts.... Read more
Affected Products : phpprofiles- Published: Dec. 26, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2000-0879
LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.... Read more
Affected Products : lpplus- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-8733
Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.... Read more
Affected Products : cloudera_manager- Published: Feb. 10, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-0527
EMC Documentum xCelerated Management System (xMS) 1.1 before P14 stores cleartext Windows Service credentials in a batch file during Documentum Platform and xCelerated Composition Platform (xCP) provisioning, which allows local users to obtain sensitive i... Read more
Affected Products : documentum_xcelerated_management_system- Published: Mar. 24, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-3264
The engine installer in Novell Identity Manager (aka IDM) 3.6.1 stores admin tree credentials in /tmp/idmInstall.log, which allows local users to obtain sensitive information by reading this file.... Read more
Affected Products : identity_manager- Published: Sep. 08, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-4862
The Host Connect emulator in IBM Rational Developer for System z 7.1 through 8.5.1 does not properly store the SSL certificate password, which allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : rational_developer_for_system_z- Published: Dec. 05, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-1640
Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1... Read more
- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2004-1894
TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.... Read more
Affected Products : context- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2011-2327
Unspecified vulnerability in the Oracle Communications Unified component in Oracle Sun Products Suite 7.0 allows local users to affect confidentiality via unknown vectors related to Delegated Administrator.... Read more
Affected Products : sun_products_suite- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-9740
Cross-site scripting (XSS) vulnerability in the Rules Link module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer rules links" permission to inject arbitrary web script or HTML via unspecified vectors, which are no... Read more
Affected Products : rules_link- Published: Jul. 06, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2005-1915
The log4sh_readProperties function in log4sh 1.2.5 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable log4sh.$$ filenames.... Read more
Affected Products : log4sh- Published: Sep. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1023
Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, in... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1494
colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argument.... Read more
Affected Products : irix- Published: Aug. 09, 1994
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-3723
The process scheduler in the Sun Solaris kernel does not make use of the process statistics kept by the kernel and performs scheduling based upon CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of serv... Read more
Affected Products : solaris- Published: Jul. 12, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2012-5635
The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files created by (1) tests/volume.rc, (2) extras/hook-scripts/S... Read more
- Published: Apr. 09, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2025-43753
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.1 through 2024.Q2.13, 2024.Q1.1 through ... Read more
- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Cross-Site Scripting
-
2.1
LOWCVE-2009-5056
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then... Read more
Affected Products : otrs- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-3539
Unspecified vulnerability in HP OpenView Select Identity (HPSI) Connectors on Windows, as used in HPSI Active Directory Connector 2.30 and earlier, HPSI SunOne Connector 1.14 and earlier, HPSI eDirectory Connector 1.12 and earlier, HPSI eTrust Connector 1... Read more
- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2000-0387
The makelev program in the golddig game from the FreeBSD ports collection allows local users to overwrite arbitrary files.... Read more
Affected Products : golddig- Published: May. 09, 2000
- Modified: Apr. 03, 2025