Latest CVE Feed
-
3.7
LOWCVE-2008-1696
Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the prefixdir parameter.... Read more
Affected Products : dazphpnews- Published: Apr. 08, 2008
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2025-4654
The Soumettre.fr plugin for WordPress is vulnerable to unauthorized access and modification of data due to a improper authorization checks on the make_signature function in all versions up to, and including, 2.1.5. This makes it possible for unauthenticat... Read more
Affected Products :- Published: Jul. 02, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
3.7
LOWCVE-1999-0401
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.... Read more
Affected Products : linux_kernel- Published: Jan. 01, 1999
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2001-0627
vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : openserver- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-1999-0141
Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.... Read more
Affected Products : navigator- Published: Mar. 29, 1996
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-1999-0123
Race condition in Linux mailx command allows local users to read user files.... Read more
Affected Products : slackware_linux- Published: Dec. 01, 1995
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2001-0317
Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.... Read more
Affected Products : linux_kernel- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2006-1174
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly ... Read more
Affected Products : shadow- Published: May. 28, 2006
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2013-7347
Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to gain access to the session by reading the __ac session cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2012-335... Read more
- Published: Mar. 31, 2014
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2005-1768
Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that... Read more
Affected Products : linux_kernel- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2002-0430
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2023-38546
This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for s... Read more
- Published: Oct. 18, 2023
- Modified: Feb. 13, 2025
-
3.7
LOWCVE-2024-10977
Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to the libpq application. For example, a man-in-the-middle attacker could send a long error message that a h... Read more
Affected Products : postgresql- Published: Nov. 14, 2024
- Modified: Feb. 20, 2025
-
3.7
LOWCVE-2015-7408
The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy auth... Read more
Affected Products : tivoli_storage_manager- Published: Feb. 15, 2016
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2015-4834
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Zones.... Read more
Affected Products : solaris- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2000-1162
ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.... Read more
Affected Products : ghostscript- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2021-2448
Vulnerability in the Oracle Financial Services Crime and Compliance Investigation Hub product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 20.1.2. Difficult to exploit vulnerability allows high ... Read more
Affected Products : financial_services_crime_and_compliance_investigation_hub- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-7883
When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function call is made that returns a floating-point value and when this is the first us... Read more
Affected Products :- Published: Oct. 31, 2024
- Modified: Nov. 01, 2024
-
3.7
LOWCVE-2005-0953
Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.... Read more
Affected Products : bzip2- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2025-47295
A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the FGFM daemon via a specially crafted request, under rare condition... Read more
Affected Products : fortios- Published: May. 28, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Denial of Service