Latest CVE Feed
-
1.8
LOWCVE-2012-2424
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allow remote attackers to cause a denial of service (NULL pointer derefer... Read more
- EPSS Score: %0.18
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2017-10122
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure whe... Read more
- EPSS Score: %0.09
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
1.8
LOWCVE-2012-2425
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, allow remote attackers to cause a denial of service (application crash) v... Read more
- EPSS Score: %0.21
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2014-4812
The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, which allows remote attackers to obtain sensitive information by connecting to this port.... Read more
Affected Products : security_appscan_source- EPSS Score: %0.11
- Published: Oct. 26, 2014
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2024-2567
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in jurecapuder AndroidWeatherApp 1.0.0 on Android. Affected is an unknown function of the file androidmanifest.xml of the component Backup File Handler. The ma... Read more
Affected Products :- Published: Mar. 17, 2024
- Modified: Nov. 21, 2024
-
1.8
LOWCVE-2024-12057
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the ... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
1.7
LOWCVE-2006-0956
nuauth in NuFW before 1.0.21 does not properly handle blocking TLS sockets, which allows remote authenticated users to cause a denial of service (service hang) by flooding packets at the authentication server.... Read more
Affected Products : nufw_firewall- EPSS Score: %0.24
- Published: Mar. 02, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2014-2603
Unspecified vulnerability on HP 8/20q switches, SN6000 switches, and 8Gb Simple SAN Connection Kit with firmware before 8.0.14.08.00 allows remote authenticated users to obtain sensitive information via unknown vectors.... Read more
Affected Products : hp_h-series_fibre_channel_switch_firmware 8\/20q_fibre_channel_switch_16_port 8\/20q_fibre_channel_switch_8_port 8gb_simple_san_connection_kit sn6000_stackable_8gb_12-port_single_power_fibre_channel_switch sn6000_stackable_8gb_24-port_dual_power_fibre_channel_switch sn6000_stackable_8gb_24-port_single_power_fibre_channel_switch- EPSS Score: %0.25
- Published: May. 10, 2014
- Modified: Apr. 12, 2025
-
1.7
LOWCVE-2006-6653
The accept function in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (socket consumption) via an invalid (1) name or (2) namelen parameter, which may re... Read more
Affected Products : netbsd- EPSS Score: %0.06
- Published: Dec. 20, 2006
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2006-4642
AuditWizard 6.3.2, when using "Remote Audit," logs the administrator password in plaintext to LaytonCmdSvc.log, which allows local users to obtain sensitive information by reading the file.... Read more
Affected Products : auditwizard- EPSS Score: %0.07
- Published: Sep. 08, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2002-0415
Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275.... Read more
Affected Products : realplayer- EPSS Score: %0.37
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2009-0905
IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.... Read more
Affected Products : websphere_mq- EPSS Score: %0.05
- Published: Oct. 30, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2006-6107
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).... Read more
Affected Products : d-bus- EPSS Score: %0.10
- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2006-6510
An unspecified ActiveX control in SiteKiosk before 6.5.150 is installed "safe for scripting", which allows local users to bypass security protections and read arbitrary files via certain functions.... Read more
Affected Products : sitekiosk- EPSS Score: %0.08
- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2007-0287
Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08.... Read more
- EPSS Score: %0.37
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2007-3700
Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local u... Read more
Affected Products : java_system_access_manager- EPSS Score: %0.06
- Published: Jul. 11, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2015-4767
Unspecified vulnerability in Oracle MySQL Server 5.6.24 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Firewall, a different vulnerability than CVE-2015-4769.... Read more
- EPSS Score: %0.82
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
1.7
LOWCVE-2025-30218
Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, eve... Read more
Affected Products : next.js- Published: Apr. 02, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Misconfiguration
-
1.7
LOWCVE-2008-2619
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Application Server 1.0.2.2, 9.0.4.3, and 10.1.2.2, and E-Business Suite 11.5.10.2, allows remote authenticated users to affect availability via unknown vectors.... Read more
- EPSS Score: %0.36
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2008-1754
Symantec Altiris Deployment Solution before 6.9.164 stores the Deployment Solution Agent (aka AClient) password in cleartext in memory, which allows local users to obtain sensitive information by dumping the AClient.exe process memory.... Read more
Affected Products : altiris_deployment_solution- EPSS Score: %0.08
- Published: Apr. 11, 2008
- Modified: Apr. 09, 2025