Latest CVE Feed
-
3.7
LOWCVE-2003-0480
VMware Workstation 4.0 for Linux allows local users to overwrite arbitrary files and gain privileges via "symlink manipulation."... Read more
Affected Products : workstation- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2022-3375
An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has... Read more
Affected Products : gitlab- Published: Apr. 05, 2023
- Modified: Feb. 10, 2025
-
3.7
LOWCVE-2024-10920
A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file travels-java-api-master\src\main\java\io\github\mariazevedo88\travelsjavaapi\filters... Read more
Affected Products : travels-java-api- Published: Nov. 06, 2024
- Modified: Nov. 22, 2024
-
3.7
LOWCVE-2007-1742
suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using ... Read more
Affected Products : http_server- Published: Apr. 13, 2007
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2008-3294
src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file... Read more
Affected Products : vim- Published: Jul. 24, 2008
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2023-28858
redis-py before 4.5.3 leaves a connection open after canceling an async Redis command at an inopportune time, and can send response data to the client of an unrelated request in an off-by-one manner. NOTE: this CVE Record was initially created in response... Read more
- Published: Mar. 26, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-28322
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the s... Read more
Affected Products : fedora curl macos h300s_firmware h500s_firmware h700s_firmware h410s_firmware clustered_data_ontap ontap_antivirus_connector h300s +3 more products- Published: May. 26, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2001-1349
Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of service and possibly corrupt the heap and gain privileges via race conditions in signal handlers.... Read more
Affected Products : sendmail- Published: May. 28, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2003-1058
The Xsun server for Sun Solaris 2.6 through 9, when running in Direct Graphics Access (DGA) mode, allows local users to cause a denial of service (Xsun crash) or to create or overwrite arbitrary files on the system, probably via a symlink attack on tempor... Read more
- Published: Dec. 03, 2003
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2003-1120
Race condition in SSH Tectia Server 4.0.3 and 4.0.4 for Unix, when the password change plugin (ssh-passwd-plugin) is enabled, allows local users to obtain the server's private key.... Read more
Affected Products : tectia_server- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2000-0409
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.... Read more
Affected Products : communicator- Published: May. 10, 2000
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2023-38872
An Insecure Direct Object Reference (IDOR) vulnerability in gugoan Economizzer commit 3730880 (April 2023) and v.0.9-beta1 allows any unauthenticated attacker to access cash book entry attachments of any other user, if they know the Id of the attachment.... Read more
- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-21138
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; O... Read more
- Published: Jul. 16, 2024
- Modified: Dec. 05, 2024
-
3.7
LOWCVE-2024-21085
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22; Oracle GraalVM Enterprise Edition: 20.3.13 and... Read more
- Published: Apr. 16, 2024
- Modified: May. 21, 2025
-
3.7
LOWCVE-2021-37845
An issue was discovered in Citadel through webcit-932. A meddler-in-the-middle attacker can fixate their own session during the cleartext phase before a STARTTLS command (a violation of "The STARTTLS command is only valid in non-authenticated state." in R... Read more
Affected Products : webcit- Published: May. 29, 2023
- Modified: Jan. 14, 2025
-
3.7
LOWCVE-2023-41335
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilities—... Read more
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2015-1841
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.... Read more
Affected Products : enterprise_virtualization- Published: Sep. 08, 2015
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2012-0081
Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.1.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Administration.... Read more
Affected Products : glassfish_server- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2024-4063
A vulnerability was found in EZVIZ CS-C6-21WFR-8 5.2.7 Build 170628. It has been classified as problematic. This affects an unknown part of the component Davinci Application. The manipulation leads to improper certificate validation. It is possible to ini... Read more
Affected Products :- Published: Apr. 23, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-4596
A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Session Handler. The manipulation of the argument PHPSESSIONID leads to information disclosure. The attack... Read more
Affected Products : kimai- Published: May. 07, 2024
- Modified: Nov. 21, 2024