Latest CVE Feed
-
2.1
LOWCVE-2024-51752
The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are logged to the console when the disabled by default `debug` flag, is enabled.... Read more
Affected Products : authkit- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
2.1
LOWCVE-2013-6986
The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to obtain sensitive information by reading data elements, as demonstrated by password elements.... Read more
Affected Products : subway_ordering_for_california- EPSS Score: %0.07
- Published: Dec. 12, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-1970
The IBM WebSphere DataPower XC10 appliance 2.1 through 2.1.0.3 and 2.5 through 2.5.0.4 retains data on SSD cards, which might allow physically proximate attackers to obtain sensitive information by extracting a card and attaching it elsewhere.... Read more
Affected Products : websphere_datapower_xc10_appliance_firmware- EPSS Score: %0.06
- Published: Aug. 03, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2015-4824
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- EPSS Score: %0.17
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-0227
Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.... Read more
- EPSS Score: %0.20
- Published: Mar. 19, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-0296
Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.... Read more
- EPSS Score: %0.36
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-7128
Valve Bug Reporter in the valve-bugreporter package 2.10+bsos1 in Valve SteamOS Beta stores cleartext credentials in a .valve-bugreporter.cfg file upon a Remember Credentials action, which allows local users to obtain sensitive information by reading this... Read more
Affected Products : steamos- EPSS Score: %0.06
- Published: Dec. 17, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0652
lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 and 2.07 allows local users to cause a denial of service (crash) via a crafted 0x80000064 IOCTL request that triggers an assertion failure. NOTE: some of these details are obtained from third part... Read more
Affected Products : look_\'n\'_stop_firewall- EPSS Score: %0.23
- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-6117
Aeolus Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for /var/log/aeolus-configserver/configserver.log, which allows local users to read plaintext passwords by reading the log file.... Read more
- EPSS Score: %0.10
- Published: Mar. 12, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2001-0078
in.mond in Sun Cluster 2.x allows local users to read arbitrary files via a symlink attack on the status file of a host running HA-NFS.... Read more
Affected Products : cluster- EPSS Score: %0.10
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0596
The Equalizer Load-balancer for serial network interfaces (eql.c) in Linux kernel 2.6.x up to 2.6.7 allows local users to cause a denial of service via a non-existent device name that triggers a null dereference.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1587
NetBSD 1.6 up to 3.0, when a user has "set record" in .mailrc with the default umask set, creates the record file with 0644 permissions, which allows local users to read the record file.... Read more
Affected Products : netbsd- EPSS Score: %0.06
- Published: Apr. 03, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-1744
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.5 and 8.3.7 allows context-dependent users to affect availability via unknown vectors related to Outside In Filters.... Read more
Affected Products : fusion_middleware- EPSS Score: %4.64
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2002-0577
Vulnerability in passwd for HP-UX 11.00 and 11.11 allows local users to corrupt the password file and cause a denial of service.... Read more
Affected Products : hp-ux- EPSS Score: %0.10
- Published: Jun. 18, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-1495
xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.... Read more
Affected Products : suse_linux- EPSS Score: %0.06
- Published: Feb. 18, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0473
The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.... Read more
Affected Products : rsync- EPSS Score: %0.10
- Published: Apr. 07, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-1970
SnortCenter 0.9.5, when configured to push Snort rules, stores the rules in a temporary file with world-readable and world-writable permissions, which allows local users to obtain usernames and passwords for the alert database servers.... Read more
Affected Products : snortcenter- EPSS Score: %0.05
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2003-1065
Unknown vulnerability in patches 108993-14 through 108993-19 and 108994-14 through 108994-19 for Solaris 8 may allow local users to cause a denial of service (automountd crash).... Read more
- EPSS Score: %0.06
- Published: Jul. 23, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2002-0234
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consume... Read more
Affected Products : netscreen_screenos- EPSS Score: %0.08
- Published: May. 29, 2002
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-2477
DiamondCS Process Guard Free 2.000 allows local users to disable the process guard protection system by overwriting the current Service Descriptor Table (SDT) in \device\physicalmemory with the original SDT found in ntoskrnl.exe.... Read more
Affected Products : process_guard_free- EPSS Score: %0.12
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025