Latest CVE Feed
-
4.0
MEDIUMCVE-2009-0320
Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to ... Read more
- Published: Jan. 28, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2013-3300
The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users' sessions via invalid input data containing a... Read more
Affected Products : lift- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2004-2488
Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.... Read more
Affected Products : nexgen_ftp_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2014-2346
COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow physically proximate attackers to cause a denial of service (infinite loop and ... Read more
- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-3141
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0.0 through 11.2.0 allows remote authenticated users to affect integrity, rel... Read more
Affected Products : financial_services_software- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2004-2584
frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a ... Read more
Affected Products : smartermail- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0613
Unspecified vulnerability in Java Web Start after 1.0.1_02, as used in J2SE 5.0 Update 5 and earlier, allows remote attackers to obtain privileges via unspecified vectors involving untrusted applications.... Read more
- Published: Feb. 09, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2012-4487
The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching to a subuser they created.... Read more
- Published: Nov. 02, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2008-5678
Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (... Read more
Affected Products : olib7_webview- Published: Dec. 19, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2012-4585
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to read arbitrary files via a crafted URL.... Read more
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2025-20980
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Memory Corruption
-
4.0
MEDIUMCVE-2020-4906
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.... Read more
- Published: Dec. 16, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2024-34670
Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
4.0
MEDIUMCVE-2020-4846
IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-... Read more
Affected Products : security_key_lifecycle_manager- Published: Dec. 17, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2007-0564
The license registering interface in Symantec Web Security (SWS) before 3.0.1.85 allows attackers to cause a denial of service (CPU consumption) by submitting a large file.... Read more
Affected Products : web_security- Published: Jan. 30, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-0997
Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, related to DBMS_SYS_SQL.... Read more
Affected Products : database_server- Published: Apr. 15, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2018-11352
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the config... Read more
Affected Products : wallabag- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2009-4328
Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (server trap) by calling a SQL stored procedure in unknown circumstances.... Read more
Affected Products : db2- Published: Dec. 16, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2018-12037
An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the... Read more
Affected Products : t5_firmware 840_evo_firmware 850_evo_firmware t3_firmware crucial_mx100_firmware crucial_mx200_firmware crucial_mx300_firmware 840_evo 850_evo t3 +4 more products- Published: Nov. 20, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-3713
Unspecified vulnerability in OC4J for Oracle Application Server 10.1.3.0 has unknown impact and attack vectors, aka Oracle Vuln# AS09.... Read more
Affected Products : application_server- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025