Low Severity Vulnerabilities

9.9K CVEs classified as low severity

LOW
Total CVEs
9.9K
Vulnerabilities
Avg CVSS
2.4
Low
Max CVSS
3.6
Highest
Min CVSS
2.1
Lowest

Browse by Severity

Low Severity CVEs

Page 409 of 412
CVSS:2.1(Low)

Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.

CVSS:2.1(Low)

Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse properly.

CVSS:3.6(Low)

The default permissions for Endymion MailMan allow local users to read email or modify files.

CVSS:3.6(Low)

UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.

CVSS:2.6(Low)

By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.

CVSS:3.6(Low)

The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.

CVSS:2.1(Low)

The fwluser script in AIX eNetwork Firewall allows local users to write to arbitrary files via a symlink attack.

CVSS:2.6(Low)

NIS finger allows an attacker to conduct a denial of service via a large number of finger requests, resulting in a large number of NIS queries.

CVSS:2.6(Low)

Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.

CVSS:2.1(Low)

KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable.

CVSS:2.1(Low)

Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unrespo...

CVSS:2.6(Low)

When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information.

CVSS:2.1(Low)

The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.

CVSS:2.6(Low)

Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.

CVSS:2.1(Low)

Denial of service in BSDi Symmetric Multiprocessing (SMP) when an fstat call is made when the system has a high CPU load.

CVSS:2.1(Low)

The logging facility of the Debian smtp-refuser package allows local users to delete arbitrary files using symbolic links.

CVSS:2.1(Low)

A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.