Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-15340 1 Savannah 1 Lwip Smtp Client 2026-10-11 9.8 Critical
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
CVE-2024-27630 2 Gnu, Savannah 2 Savane, Savane 2025-09-02 7.5 High
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file function.
CVE-2024-27632 2 Gnu, Savannah 2 Savane, Savane 2025-09-02 8.8 High
An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.