Latest CVE Feed
-
4.0
MEDIUMCVE-2008-5846
Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."... Read more
Affected Products : movable_type- Published: Jan. 05, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-6658
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter duri... Read more
Affected Products : simple_machines_forum- Published: Apr. 07, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-7182
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND comm... Read more
Affected Products : surgemail- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-7264
The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed data-transfer attempt.... Read more
Affected Products : pyftpdlib- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2008-6199
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via a direct request to backup.php, which creates backup.sql under the web root with insufficient access control.... Read more
Affected Products : 2532gigs- Published: Feb. 20, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-7287
Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allow remote authenticated users to cause a denial of service (memory consumption) by making ma... Read more
Affected Products : tivoli_directory_server- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2024-54731
cpdf through 2.8 allows stack consumption via a crafted PDF document.... Read more
Affected Products :- Published: Jan. 08, 2025
- Modified: Jan. 08, 2025
- Vuln Type: Denial of Service
-
4.0
MEDIUMCVE-2007-6734
NWFTPD.nlm before 5.08.07 in the FTP server in Novell NetWare 6.5 SP7 does not properly implement the FTPREST.TXT NOREMOTE restriction, which allows remote authenticated users to access directories outside of the home server via unspecified vectors.... Read more
- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2008-0615
Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters.... Read more
Affected Products : dmsguestbook- Published: Feb. 06, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2025-20940
Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.... Read more
Affected Products :- Published: Apr. 08, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2025-20993
Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.... Read more
Affected Products :- Published: Jun. 04, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Memory Corruption
-
4.0
MEDIUMCVE-2007-6740
The ftp_STOU function in FTPServer.py in pyftpdlib before 0.2.0 does not limit the number of attempts to discover a unique filename, which might allow remote authenticated users to cause a denial of service via a STOU command.... Read more
Affected Products : pyftpdlib- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2008-1263
The Linksys WRT54G router stores passwords and keys in cleartext in the Config.bin file, which might allow remote authenticated users to obtain sensitive information via an HTTP request for the top-level Config.bin URI.... Read more
- Published: Mar. 10, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-1528
ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated... Read more
- Published: Mar. 26, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2016-3972
Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.... Read more
Affected Products : dotcms- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2006-2449
KDE Display Manager (KDM) in KDE 3.2.0 up to 3.5.3 allows local users to read arbitrary files via a symlink attack related to the session type for login.... Read more
- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2025-49128
Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. Starting in version 2.0.0 and prior to version 2.13.0, a flaw in jackson-core's `JsonLocation._appendSourceDesc` method allows... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
4.0
MEDIUMCVE-2007-4669
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148.... Read more
- Published: Sep. 04, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-0615
Multiple unspecified vulnerabilities in Sun Java JDK and JRE 5.0 Update 4 and earlier, SDK and JRE 1.4.x through 1.4.2_09 allow remote attackers to bypass Java sandbox security and obtain privileges via unspecified vectors involving the reflection APIs, a... Read more
- Published: Feb. 09, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2016-3024
IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the system.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025