Latest CVE Feed
-
9.8
CRITICAL- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2006-7254
The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allowing local users to carry out a denial of service attack on the daemon.... Read more
Affected Products : glibc- Published: Apr. 10, 2019
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2006-7246
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.... Read more
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2006-4245
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.... Read more
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-4243
linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.... Read more
- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2006-10001
A vulnerability, which was classified as problematic, was found in Subscribe to Comments Plugin up to 2.0.7 on WordPress. This affects an unknown part of the file subscribe-to-comments.php. The manipulation leads to cross site scripting. It is possible to... Read more
- Published: Mar. 05, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2006-0062
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.... Read more
Affected Products : xlockmore- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2006-0061
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.... Read more
Affected Products : xlockmore- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-4891
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.... Read more
Affected Products : simple_machine_forum- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2005-4890
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the ... Read more
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-3590
The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corru... Read more
Affected Products : glibc- Published: Apr. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-3056
TWiki allows arbitrary shell command execution via the Include function... Read more
Affected Products : twiki- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2005-2354
Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.... Read more
Affected Products : nvu- Published: Nov. 05, 2019
- Modified: Nov. 20, 2024
-
8.1
HIGHCVE-2005-2352
I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.... Read more
Affected Products : gs-gpl- Published: Nov. 01, 2019
- Modified: Nov. 20, 2024
-
5.5
MEDIUMCVE-2005-2351
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.... Read more
- Published: Nov. 01, 2019
- Modified: Nov. 20, 2024
-
6.1
MEDIUMCVE-2005-2350
Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.... Read more
Affected Products : websieve- Published: Nov. 01, 2019
- Modified: Nov. 20, 2024
-
7.5
HIGH- Published: Oct. 28, 2019
- Modified: Nov. 20, 2024
-
9.8
CRITICALCVE-2005-10002
A vulnerability, which was classified as critical, was found in almosteffortless secure-files Plugin up to 1.1 on WordPress. Affected is the function sf_downloads of the file secure-files.php. The manipulation of the argument downloadfile leads to path tr... Read more
Affected Products : secure_files- Published: Oct. 29, 2023
- Modified: Nov. 20, 2024
-
6.1
MEDIUMCVE-2005-10001
A vulnerability was found in Netegrity SiteMinder up to 4.5.1 and classified as critical. Affected by this issue is the file /siteminderagent/pwcgi/smpwservicescgi.exe of the component Login. The manipulation of the argument target leads to an open redire... Read more
Affected Products : symantec_siteminder- Published: Mar. 28, 2022
- Modified: Nov. 20, 2024