Latest CVE Feed
-
1.2
LOWCVE-2002-2001
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.15
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2002-0435
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it ... Read more
- EPSS Score: %0.07
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-2449
Race condition in sandbox before 1.2.11 allows local users to create or overwrite arbitrary files via symlink attack on sandboxpids.tmp.... Read more
Affected Products : sandbox- EPSS Score: %0.10
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2012-2103
The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.... Read more
Affected Products : munin- EPSS Score: %0.04
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2005-2527
Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack vectors related to a temporary directory, possibly due to a symlink attack.... Read more
Affected Products : java- EPSS Score: %0.04
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2012-0645
Siri in Apple iOS before 5.1 does not properly restrict the ability of Mail.app to handle voice commands, which allows physically proximate attackers to bypass the locked state via a command that forwards an active e-mail message to an arbitrary recipient... Read more
Affected Products : iphone_os- EPSS Score: %0.09
- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2010-3014
The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which trigger... Read more
- EPSS Score: %0.07
- Published: Aug. 20, 2010
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2006-6306
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.... Read more
Affected Products : client- EPSS Score: %0.08
- Published: Dec. 05, 2006
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2001-1146
AllCommerce with debugging enabled in EnGarde Secure Linux 1.0.1 creates temporary files with predictable names, which allows local users to modify files via a symlink attack.... Read more
Affected Products : allcommerce- EPSS Score: %0.11
- Published: Jul. 11, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-4660
Race condition in IPCop (aka IPCop Firewall) before 1.4.10 might allow local users to overwrite system configuration files and gain privileges by replacing a backup archive during the time window when the archive is owned by "nobody" but not yet encrypted... Read more
Affected Products : ipcop- EPSS Score: %0.07
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1878
GIPTables Firewall 1.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the temp.ip.addresses temporary file.... Read more
Affected Products : giptables_firewall- EPSS Score: %0.07
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2000-0224
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.... Read more
Affected Products : unixware- EPSS Score: %0.25
- Published: Feb. 15, 2000
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1824
Multiple cross-site scripting (XSS) vulnerabilities in PhpGuestbook.php in PhpGuestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Website, and (3) Comment parameter.... Read more
Affected Products : phpguestbook- EPSS Score: %0.16
- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2007-3108
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.... Read more
Affected Products : openssl- EPSS Score: %0.10
- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2005-1368
The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP.... Read more
Affected Products : linux_kernel- EPSS Score: %0.07
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2011-4415
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of environment variables, which allows local users to cause a d... Read more
Affected Products : http_server- EPSS Score: %0.77
- Published: Nov. 08, 2011
- Modified: Apr. 11, 2025
-
1.1
LOWCVE-2025-46735
Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. ... Read more
Affected Products :- Published: May. 06, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
1.1
LOWCVE-2024-51991
October is a Content Management System (CMS) and web platform. A vulnerability in versions prior to 3.7.5 affects authenticated administrators with sites that have the `media.clean_vectors` configuration enabled. This configuration will sanitize SVG files... Read more
Affected Products : october- Published: May. 05, 2025
- Modified: May. 05, 2025
- Vuln Type: Misconfiguration
-
1.0
LOWCVE-2025-3301
DPA countermeasures are unavailable for ECDH key agreement and EdDSA signing operations on Curve25519 and Curve448 on all Series 2 modules and SoCs due to a lack of hardware and software support. A successful DPA attack may result in exposure of confident... Read more
Affected Products :- Published: Apr. 29, 2025
- Modified: May. 02, 2025
- Vuln Type: Cryptography
-
1.0
LOWCVE-2025-24959
zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended environment variables into `process.env`. This can lead to arbitrary command execution or unexpected behavior in applications that rel... Read more
Affected Products :- Published: Feb. 03, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Injection