Latest CVE Feed
-
2.1
LOWCVE-2010-2975
Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 does not properly handle multiple SSH sessions, which allows physically proximate attackers to read a password, related to an "arrow key failure," aka Bug ID CSCtg51544.... Read more
Affected Products : unified_wireless_network_solution_software- Published: Aug. 10, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-1629
Cross-site scripting (XSS) vulnerability in the Taxotouch module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 20, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-1648
Cross-site scripting (XSS) vulnerability in the Cool Aid module before 6.x-1.9 for Drupal allows remote authenticated users with the administer coolaid permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 09, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-0519
The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 places a cleartext InputAccel (IA) SQL password in a DAL log file, which allows local users to obtain sensitive information by reading a... Read more
Affected Products : captiva_capture- Published: Feb. 14, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6181
EMC Watch4Net before 6.3 stores cleartext polled-device passwords in the installation repository, which allows local users to obtain sensitive information by leveraging repository privileges.... Read more
Affected Products : watch4net- Published: Dec. 28, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-4452
Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication credentials and other unspecified sensitive information by reading these files.... Read more
Affected Products : jboss_operations_network- Published: Dec. 24, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-1602
Siemens SIMATIC STEP 7 (TIA Portal) 12 and 13 before 13 SP1 Upd1 improperly stores password data within project files, which makes it easier for local users to determine cleartext (1) protection-level passwords or (2) web-server passwords by leveraging th... Read more
Affected Products : simatic_step_7- Published: Apr. 06, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2011-3522
Unspecified vulnerability in SysFW 8.0 on certain SPARC T3, Netra SPARC T3, Sun Fire, and Sun Blade based servers allows local users to affect confidentiality, related to Integrated Lights Out Manager CLI.... Read more
Affected Products : netra_sparc_t3-1 sparc_t3-1 sparc_t3-1b sparc_t3-4 sun_blade_x6270 sun_blade_x6270_m2 sun_blade_x6275 sun_blade_x6275_m2 sun_blade_x6440_m2 sun_blade_x6450 +9 more products- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-3488
Cross-site scripting (XSS) vulnerability in the Bibliography (aka Biblio) module 6.x-1.6 for Drupal allows remote authenticated users, with certain content-creation privileges, to inject arbitrary web script or HTML via the Title field, probably a differe... Read more
- Published: Sep. 30, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2012-3191
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote authenticated users to affect availability via unknown vectors related to Data Mover.... Read more
Affected Products : peoplesoft_products- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-3206
Unspecified vulnerability in the Integrated Lights Out Manager CLI in Oracle Sun Products Suite SysFW 8.2.0.a for SPARC and Netra SPARC T3 and T4-based servers, and other versions and servers, allows local users to affect confidentiality via unknown vecto... Read more
Affected Products : netra_sparc_t3-1 sparc_t3-1 sparc_t3-1b sparc_t3-4 netra_sparc_t3-1b sparc_t3-2 sparc_t4-1 sparc_t4-1b sparc_t4-4 sun_products_suite_sysfw +3 more products- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-3982
The Fibre Channel driver for QLogic adapters in IBM AIX 6.1 and 7.1 does not properly handle DMA resource limitations, which allows local users to cause a denial of service (system hang) via vectors that generate a large amount of DMA I/O, related to a de... Read more
Affected Products : aix- Published: Oct. 05, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-5705
Cross-site scripting (XSS) vulnerability in the settings page (admin/settings/hotblocks) in the Hotblocks module 6.x-1.x before 6.x-1.8 for Drupal allows remote authenticated users with the "administer hotblocks" permission to inject arbitrary web script ... Read more
- Published: Nov. 01, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2017-2752
A potential security vulnerability caused by incomplete obfuscation of application configuration information was discovered in Tommy Hilfiger TH24/7 Android app versions 2.0.0.11, 2.0.1.14, 2.1.0.16, and 2.2.0.19. HP has no access to customer data as a re... Read more
Affected Products : tommy_hilfiger_th24\/7- Published: Mar. 27, 2019
- Modified: Nov. 21, 2024
-
2.1
LOWCVE-2014-3851
usr/lib/cgi-bin/create_passwd_file.py in Pyplate 0.08 uses world-readable permissions for passwd.db, which allows local users to obtain the administrator password by reading this file.... Read more
Affected Products : pyplate- Published: Aug. 07, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-1650
Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "other" readable) under opt/open-xchange/etc/, which allows local users to obtain sensitive information via standard filesystem operations.... Read more
Affected Products : open-xchange_server- Published: Sep. 05, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-0170
IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows local users to obtain sensitive information by reading cached data.... Read more
Affected Products : security_siteprotector_system- Published: May. 25, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-5964
Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "Administer flags" permission to inject arbitrary web script or HTML via the flag title.... Read more
- Published: Sep. 30, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2008-7292
Bugzilla 2.20.x before 2.20.5, 2.22.x before 2.22.3, and 3.0.x before 3.0.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files, a different v... Read more
- Published: Aug. 09, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-4506
Cross-site scripting (XSS) vulnerability in the Custom Meta module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer custom meta settings" permission to inject arbitrary web script or HTML ... Read more
Affected Products : custom_meta- Published: Jun. 20, 2014
- Modified: Apr. 12, 2025