Latest CVE Feed
-
2.1
LOWCVE-2007-3723
The process scheduler in the Sun Solaris kernel does not make use of the process statistics kept by the kernel and performs scheduling based upon CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of serv... Read more
Affected Products : solaris- Published: Jul. 12, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-1360
Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle.... Read more
Affected Products : windows_nt- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2001-0261
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.... Read more
Affected Products : windows_2000- Published: Jun. 02, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1441
Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it.... Read more
Affected Products : linux_kernel- Published: Jun. 30, 1998
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0269
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.... Read more
Affected Products : emacs- Published: Apr. 18, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3620
The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to ... Read more
Affected Products : esx- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-4380
Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web s... Read more
- Published: May. 20, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-1587
NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.... Read more
Affected Products : netbsd- Published: Apr. 03, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-1018
shred 1.0 file wiping utility does not properly open a file for overwriting or flush its buffers, which prevents shred from properly replacing the file's data and allows local users to recover the file.... Read more
Affected Products : shred- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1682
JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeaders, which allows remote authenticated users to read other users' e-mail messa... Read more
Affected Products : solstice_internet_mail_server- Published: May. 20, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1023
Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, in... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2134
The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same i... Read more
Affected Products : netbsd- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2010-2612
Unspecified vulnerability in the HP OpenVMS Auditing feature in OpenVMS ALPHA 7.3-2, 8.2, and 8.3; and OpenVMS for Integrity Servers 8.3 AND 8.3-1H1; allows local users to obtain sensitive information via unknown vectors.... Read more
- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-0227
Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.... Read more
- Published: Mar. 19, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-1956
The create_user_ns function in kernel/user_namespace.c in the Linux kernel before 3.8.6 does not check whether a chroot directory exists that differs from the namespace root directory, which allows local users to bypass intended filesystem restrictions vi... Read more
Affected Products : linux_kernel- Published: Apr. 24, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-4824
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-7128
Valve Bug Reporter in the valve-bugreporter package 2.10+bsos1 in Valve SteamOS Beta stores cleartext credentials in a .valve-bugreporter.cfg file upon a Remember Credentials action, which allows local users to obtain sensitive information by reading this... Read more
Affected Products : steamos- Published: Dec. 17, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-2297
Multiple cross-site scripting (XSS) vulnerabilities in the Creative Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote authenticated users with the administer creative commons permission to inject arbitrary web script or HTML via the (1) creati... Read more
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-2201
The screensharing feature in the Admin application in Apple Xsan before 2.2 places a cleartext username and password in a URL within an error dialog, which allows physically proximate attackers to obtain credentials by reading this dialog.... Read more
Affected Products : xsan- Published: Sep. 15, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2024-50403
A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to obtain secret data or modif... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024