Latest CVE Feed
-
1.7
LOWCVE-2025-30218
Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, eve... Read more
Affected Products : next.js- Published: Apr. 02, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Misconfiguration
-
1.7
LOWCVE-2013-1499
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Network Configuration.... Read more
- EPSS Score: %0.05
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2007-0288
Unspecified vulnerability in Oracle Application Server 10.1.4.0 has unknown impact and attack vectors related to Oracle Internet Directory, aka OID01.... Read more
Affected Products : application_server- EPSS Score: %0.37
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2007-3700
Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local u... Read more
Affected Products : java_system_access_manager- EPSS Score: %0.06
- Published: Jul. 11, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2014-2603
Unspecified vulnerability on HP 8/20q switches, SN6000 switches, and 8Gb Simple SAN Connection Kit with firmware before 8.0.14.08.00 allows remote authenticated users to obtain sensitive information via unknown vectors.... Read more
Affected Products : hp_h-series_fibre_channel_switch_firmware 8\/20q_fibre_channel_switch_16_port 8\/20q_fibre_channel_switch_8_port 8gb_simple_san_connection_kit sn6000_stackable_8gb_12-port_single_power_fibre_channel_switch sn6000_stackable_8gb_24-port_dual_power_fibre_channel_switch sn6000_stackable_8gb_24-port_single_power_fibre_channel_switch- EPSS Score: %0.25
- Published: May. 10, 2014
- Modified: Apr. 12, 2025
-
1.7
LOWCVE-2009-0905
IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow local users to gain privileges by leveraging combinations of group names with the same initial substring.... Read more
Affected Products : websphere_mq- EPSS Score: %0.05
- Published: Oct. 30, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2008-0996
The Printing component in Apple Mac OS X 10.5.2 might save authentication credentials to disk when starting a job on an authenticated print queue, which might allow local users to obtain the credentials.... Read more
- EPSS Score: %0.06
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2006-0386
FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.... Read more
- EPSS Score: %0.07
- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2013-0982
The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattend... Read more
- EPSS Score: %0.05
- Published: Jun. 05, 2013
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2011-0796
Unspecified vulnerability in the Applications Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows local users to affect confidentiality via unknown vectors.... Read more
Affected Products : e-business_suite- EPSS Score: %0.08
- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2007-0294
Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning & Data Guard Management, aka EM06.... Read more
Affected Products : enterprise_manager- EPSS Score: %0.37
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2002-0415
Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275.... Read more
Affected Products : realplayer- EPSS Score: %0.37
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2006-4642
AuditWizard 6.3.2, when using "Remote Audit," logs the administrator password in plaintext to LaytonCmdSvc.log, which allows local users to obtain sensitive information by reading the file.... Read more
Affected Products : auditwizard- EPSS Score: %0.07
- Published: Sep. 08, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2006-0920
Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password.... Read more
Affected Products : email_marketing_system- EPSS Score: %0.17
- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2013-2382
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows local users to affect confidentiality via vectors related to BASE.... Read more
Affected Products : financial_services_software- EPSS Score: %0.15
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2011-2311
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability, related to ZFS, a different vulnerability than CVE-2011-2313.... Read more
Affected Products : solaris- EPSS Score: %0.09
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2009-3401
Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows local users to affect confidentiality via unknown vectors.... Read more
Affected Products : e-business_suite- EPSS Score: %0.23
- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2011-3539
Unspecified vulnerability in Oracle Solaris 10 and 11 Express allows local users to affect availability via unknown vectors related to Zones.... Read more
Affected Products : solaris- EPSS Score: %0.10
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2006-6655
The procfs implementation in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (kernel panic) by attempting to access /emul/linux/proc/0/stat on a procfs fi... Read more
Affected Products : netbsd- EPSS Score: %0.06
- Published: Dec. 20, 2006
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2003-0986
Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to caus... Read more
- EPSS Score: %0.06
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025