CVE detail
CVE-2007-0889 — CVE-2007-0889
Published 2007-02-12 · Modified 2026-06-16 · Vendor kiwi_enterprises · Product kiwi_cattools · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0029
EPSS probability
exploitation probability, 30d
21.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Kiwi CatTools before 3.2.0 beta uses weak encryption ("reversible encoding") for passwords, account names, and IP addresses in kiwidb-cattools.kdb, which might allow local users to gain sensitive information by decrypting the file. NOTE: this issue could be leveraged with a directory traversal vulnerability for a remote attack vector.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References