Low Severity Vulnerabilities

9.9K CVEs classified as low severity

LOW
Total CVEs
9.9K
Vulnerabilities
Avg CVSS
2.4
Low
Max CVSS
3.6
Highest
Min CVSS
2.1
Lowest

Browse by Severity

Low Severity CVEs

Page 405 of 412
CVSS:2.1(Low)

Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.

CVSS:2.6(Low)

Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.

CVSS:2.1(Low)

Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.

CVSS:2.1(Low)

surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions.

CVSS:3.6(Low)

The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirectory with the victim's SID in the recycler directory, aka the "Recycle Bin Creat...

CVSS:2.1(Low)

The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Regist...

CVSS:2.1(Low)

nviboot boot script in the Debian nvi package allows local users to delete files via malformed entries in vi.recover.

CVSS:2.1(Low)

The recover program in Solstice Backup allows local users to restore sensitive files.

CVSS:2.1(Low)

CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.

CVSS:2.6(Low)

Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

CVSS:2.1(Low)

FTPPro allows local users to read sensitive information, which is stored in plain text.

CVSS:3.5(Low)

Directory traversal vulnerability in Muhammad A. Muquit wwwcount (Count.cgi) 2.3 allows remote attackers to read arbitrary GIF files via ".." sequences in the image parameter, a different vulnerabilit...

CVSS:2.1(Low)

/usr/ucb/ps in Sun Microsystems Solaris 8 and 9, and certain earlier releases, allows local users to view the environment variables and values of arbitrary processes via the -e option.

CVSS:2.1(Low)

cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and a...

CVSS:2.1(Low)

FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes.

CVSS:2.1(Low)

/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.

CVSS:2.1(Low)

Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users.

CVSS:2.1(Low)

shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code.

CVSS:2.1(Low)

When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitiv...

CVSS:3.6(Low)

cgiwrap as used on Cobalt RaQ 2.0 and RaQ 3i does not properly identify the user for running certain scripts, which allows a malicious site administrator to view or modify data located at another virt...