Latest CVE Feed
-
1.2
LOWCVE-2006-1066
Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack du... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Mar. 27, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-4232
Race condition in the grid-proxy-init tool in Globus Toolkit 3.2.x, 4.0.x, and 4.1.0 before 20060815 allows local users to steal credential data by replacing the proxy credentials file in between file creation and the check for exclusive file access.... Read more
Affected Products : globus_toolkit- EPSS Score: %0.07
- Published: Aug. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1368
The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP.... Read more
Affected Products : linux_kernel- EPSS Score: %0.07
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0095
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID temporary file.... Read more
Affected Products : sunos- EPSS Score: %0.14
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-1999-1486
sadc in IBM AIX 4.1 through 4.3, when called from programs such as timex that are setgid adm, allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : aix- EPSS Score: %0.09
- Published: Feb. 25, 1998
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0117
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.... Read more
- EPSS Score: %0.12
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-3551
NCP Secure Enterprise Client (aka VPN/PKI client) 8.30 Build 59, and possibly earlier versions, when the Link Firewall and Personal Firewall are both configured to block all inbound and outbound network traffic, allows context-dependent attackers to send ... Read more
Affected Products : secure_client- EPSS Score: %0.07
- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-2724
The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of ... Read more
Affected Products : samba- EPSS Score: %0.93
- Published: Sep. 06, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2003-0120
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.... Read more
Affected Products : mhc-utils- EPSS Score: %0.18
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-4660
Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted... Read more
Affected Products : ipcop- EPSS Score: %0.07
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-4415
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a d... Read more
Affected Products : http_server- EPSS Score: %0.77
- Published: Nov. 08, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2008-5450
Unspecified vulnerability in the Oracle Applications Platform Engineering component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows local users to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %0.20
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-1999-1042
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.... Read more
Affected Products : resource_manager- EPSS Score: %0.21
- Published: Dec. 31, 1999
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1824
Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.... Read more
Affected Products : phpguestbook- EPSS Score: %0.16
- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-1999-0475
A race condition in how procmail handles .procmailrc files allows a local user to read arbitrary files available to the user who is running procmail.... Read more
Affected Products : procmail- EPSS Score: %0.18
- Published: Apr. 05, 1999
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1167
SGI ProPack 3 SP6 kernel displays the frame buffer contents of the last session after a reboot, which might allow local users to obtain sensitive information.... Read more
Affected Products : propack- EPSS Score: %0.07
- Published: Feb. 06, 2007
- Modified: Apr. 09, 2025
-
1.1
LOWCVE-2024-51991
October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG files... Read more
Affected Products : october- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Misconfiguration
-
1.1
LOWCVE-2025-46735
Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. ... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
1.0
LOWCVE-2025-24959
zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended environment variables into `process.env`. This can lead to arbitrary command execution or unexpected behavior in applications that rel... Read more
Affected Products :- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Injection
-
1.0
LOWCVE-2009-3412
Unspecified vulnerability in the Unzip component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5; and Oracle Application Server 10.1.2.3; allows local users to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %0.24
- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025