Latest CVE Feed
-
3.7
LOWCVE-2013-5229
The Remote Desktop full-screen feature in Apple OS X before 10.9 and Apple Remote Desktop before 3.7 sends dialog-box text to a connected remote host upon being woken from sleep, which allows physically proximate attackers to bypass intended access restri... Read more
- Published: Nov. 14, 2015
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2022-2583
A race condition can cause incorrect HTTP request routing.... Read more
Affected Products : gobase- Published: Dec. 27, 2022
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2022-45433
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could get the tr... Read more
- Published: Dec. 27, 2022
- Modified: Apr. 14, 2025
-
3.7
LOWCVE-2005-0988
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after t... Read more
Affected Products : enterprise_linux enterprise_linux_desktop freebsd ubuntu_linux linux_advanced_workstation linux secure_linux turbolinux_appliance_server turbolinux_desktop turbolinux_home +3 more products- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2023-33849
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105.... Read more
- Published: Jun. 07, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-32251
A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of async... Read more
Affected Products : linux_kernel- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Authentication
-
3.7
LOWCVE-2023-34401
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the enapsulate file, attacker can achieve Out-o... Read more
Affected Products : headunit_ntg6_mercedes-benz_user_experience- Published: Feb. 13, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
3.7
LOWCVE-2022-39399
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 a... Read more
Affected Products : fedora oncommand_insight oncommand_workflow_automation jdk jre e-series_santricity_os_controller e-series_santricity_storage_manager graalvm 7-mode_transition_tool zulu +5 more products- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-41760
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51 could allow an attacker to obtain sensitive information due to a timing attack during certain RSA operations.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Cryptography
-
3.7
LOWCVE-2025-7974
rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of rocket.chat. Authentication is not required to exploit this vulnerability. ... Read more
Affected Products : rocket.chat- Published: Sep. 02, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Authorization
-
3.7
LOWCVE-2025-54568
Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separately for each edge node.... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Denial of Service
-
3.7
LOWCVE-2025-46712
Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25), Erlang/OTP SSH fails to enforce strict KEX handshake hardening measures by allo... Read more
Affected Products : otp- Published: May. 08, 2025
- Modified: May. 12, 2025
-
3.7
LOWCVE-2025-32471
The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cryptography
-
3.7
LOWCVE-2025-4215
A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular exp... Read more
- Published: May. 02, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Denial of Service
-
3.7
LOWCVE-2025-1152
A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity ... Read more
Affected Products : binutils- Published: Feb. 10, 2025
- Modified: Feb. 10, 2025
- Vuln Type: Memory Corruption
-
3.7
LOWCVE-2024-12300
The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing capability check on the set_ar_featured_image() function in all versions up to, and including, 7.3. This makes it possible for unauthenti... Read more
Affected Products : ar- Published: Dec. 13, 2024
- Modified: Dec. 13, 2024
-
3.7
LOWCVE-2023-31124
c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could a... Read more
- Published: May. 25, 2023
- Modified: Feb. 13, 2025
-
3.7
LOWCVE-2023-28858
redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner. NOTE: this CVE Record was initially created in response... Read more
- Published: Mar. 26, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-28322
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the s... Read more
Affected Products : fedora curl macos h300s_firmware h500s_firmware h700s_firmware h410s_firmware clustered_data_ontap ontap_antivirus_connector h300s +3 more products- Published: May. 26, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-25616
Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depe... Read more
Affected Products : arubaos- Published: Mar. 05, 2024
- Modified: Jul. 28, 2025