Latest CVE Feed
-
4.0
MEDIUMCVE-2010-3740
The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before FP6a does not properly handle an alphanumeric Fuzzy search, which allows remote authenticated users to cause a denial of service (memory consumption and sy... Read more
Affected Products : db2- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2008-2625
Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors. NOTE: the previous information was obtained from the O... Read more
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-4815
Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.... Read more
- Published: Apr. 27, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-0026
The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64 platform allows guest OS users to cause a denial of service (host OS hang) via a crafted application that executes a malformed series of machine instructions, ... Read more
Affected Products : windows_server_2008- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2025-21026
Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.... Read more
Affected Products : android- Published: Sep. 03, 2025
- Modified: Sep. 11, 2025
- Vuln Type: Authorization
-
4.0
MEDIUMCVE-2010-0867
Unspecified vulnerability in the JavaVM component in Oracle Database 10.2.0.4, 11.1.0.7, and 11.2.0.1.0 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : database_server- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2023-21464
Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status.... Read more
- Published: Mar. 16, 2023
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2012-0487
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0117, CVE-2012-0486, CVE-2012-0488, CVE-2012-0489, CVE-2012... Read more
Affected Products : mysql- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0454
The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users ... Read more
- Published: Mar. 26, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2007-3639
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; ... Read more
Affected Products : wordpress- Published: Jul. 10, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2007-3600
WordPlugin in the wordintegration component in vtiger CRM before 5.0.3 allows remote authenticated users to bypass field level security permissions and merge arbitrary fields in an Email template, as demonstrated by the fields in the Contact module.... Read more
Affected Products : vtiger_crm- Published: Jul. 06, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2023-50007
FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.... Read more
- Published: Apr. 19, 2024
- Modified: Jun. 06, 2025
-
4.0
MEDIUMCVE-2012-3863
channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.13.1 and 10.x before 10.5.2, Asterisk Business Edition C.3.x before C.3.7.5, Certified Asterisk 1.8.11-certx before 1.8.11-cert4, and Asterisk Digiumphones 10.x.x-digiumphones before 10.5.2-digi... Read more
- Published: Jul. 09, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2007-3037
Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that causes a size mismatch between compressed and decompressed data and triggers a heap-based... Read more
Affected Products : windows_media_player- Published: Aug. 14, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-1682
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.... Read more
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2007-4143
user.php in the Billing Control Panel in phpCoupon allows remote authenticated users to obtain Premium Member status, and possibly acquire free coupons, via a modified URL containing a certain billing parameter and REQ=auth, status=success, and custom=upg... Read more
Affected Products : phpcoupon- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2012-5375
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (prevention of file creation) by leveraging the ability to write to a directory important to the victim, and creating a file ... Read more
Affected Products : linux_kernel- Published: Feb. 18, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-5374
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (extended runtime of kernel code) by creating many different files whose names are associated with the same CRC32C hash value... Read more
Affected Products : linux_kernel- Published: Feb. 18, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2007-2407
The Samba server on Apple Mac OS X 10.3.9 and 10.4.10, when Windows file sharing is enabled, does not enforce disk quotas after dropping privileges, which allows remote authenticated users to use disk space in excess of quota.... Read more
- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-7242
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-001 does not ensure that the AE Administrator role is present for Site Preferences modifications, which allows remote authenticated users to bypass intended ac... Read more
Affected Products : filenet_p8_application_engine- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025