Latest CVE Feed
-
1.2
LOWCVE-2006-5757
Race condition in the __find_get_block_slow function in the ISO9660 filesystem in Linux 2.6.18 and possibly other versions allows local users to cause a denial of service (infinite loop) by mounting a crafted ISO9660 filesystem containing malformed data s... Read more
Affected Products : linux_kernel- EPSS Score: %0.60
- Published: Nov. 06, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2015-4823
Unspecified vulnerability in the Hyperion Installation Technology component in Oracle Hyperion 11.1.2.3 allows local users to affect confidentiality via unknown vectors related to Essbase Rapid Deploy.... Read more
Affected Products : hyperion- EPSS Score: %0.17
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2012-4676
The errorExitIfAttackViaString function in Tunnelblick 3.3beta20 and earlier allows local users to delete arbitrary files by constructing a (1) symlink or (2) hard link, a different vulnerability than CVE-2012-3485.... Read more
Affected Products : tunnelblick- EPSS Score: %0.04
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2008-5450
Unspecified vulnerability in the Oracle Applications Platform Engineering component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows local users to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %0.20
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2003-1061
Race condition in Solaris 2.6 through 9 allows local users to cause a denial of service (kernel panic), as demonstrated via the namefs function, pipe, and certain STREAMS routines.... Read more
- EPSS Score: %0.06
- Published: Oct. 14, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-6306
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.... Read more
Affected Products : client- EPSS Score: %0.08
- Published: Dec. 05, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-1999-1486
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : aix- EPSS Score: %0.09
- Published: Feb. 25, 1998
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-4761
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, 7.0 SP5 and earlier, and 6.1 SP7 and earlier log the Java command line at server startup, which might include sensitive information (passwords or keyphrases) in the server log file when the -D ... Read more
Affected Products : weblogic_server- EPSS Score: %0.11
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0117
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.... Read more
- EPSS Score: %0.12
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0224
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.... Read more
Affected Products : unixware- EPSS Score: %0.25
- Published: Feb. 15, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1824
Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.... Read more
Affected Products : phpguestbook- EPSS Score: %0.16
- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-1301
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.... Read more
- EPSS Score: %0.19
- Published: Aug. 07, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-4676
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file.... Read more
Affected Products : rendezvous- EPSS Score: %0.44
- Published: Sep. 11, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2012-3487
Race condition in Tunnelblick 3.3beta20 and earlier allows local users to kill unintended processes by waiting for a specific PID value to be assigned to a target process.... Read more
Affected Products : tunnelblick- EPSS Score: %0.02
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
1.1
LOWCVE-2024-51991
October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG files... Read more
Affected Products : october- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Misconfiguration
-
1.1
LOWCVE-2025-46735
Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. ... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
1.0
LOWCVE-2025-24959
zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended environment variables into `process.env`. This can lead to arbitrary command execution or unexpected behavior in applications that rel... Read more
Affected Products :- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Injection
-
1.0
LOWCVE-2009-3412
Unspecified vulnerability in the Unzip component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5; and Oracle Application Server 10.1.2.3; allows local users to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %0.24
- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
1.0
LOWCVE-2025-49842
conda-forge-webservices is the web app deployed to run conda-forge admin commands and linting. Prior to version 2025.3.24, the conda_forge_webservice Docker container executes commands without specifying a user. By default, Docker containers run as the ro... Read more
Affected Products :- Published: Jun. 17, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
1.0
LOWCVE-2024-12975
A buffer overread can occur in the CPC application when operating in full duplex SPI upon receiving an invalid packet over the SPI interface.... Read more
Affected Products : bluetooth_low_energy_software_development_kit- Published: Mar. 07, 2025
- Modified: Mar. 07, 2025
- Vuln Type: Memory Corruption