Latest CVE Feed
-
1.7
LOWCVE-2006-6286
Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, which allows local users to obtain sensitive information (address books, calendar files, and todo lists of other users) via unspecified vectors. NOTE: ... Read more
Affected Products : palm_desktop- EPSS Score: %0.05
- Published: Dec. 04, 2006
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2014-2926
kapfa.sys in Kaseya Virtual System Administrator (VSA) 6.5 before 6.5.0.17 and 7.0 before 7.0.0.16 allows local users to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.... Read more
Affected Products : virtual_system_administrator- EPSS Score: %0.05
- Published: Jul. 14, 2014
- Modified: Apr. 12, 2025
-
1.7
LOWCVE-2025-30218
Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, eve... Read more
Affected Products : next.js- Published: Apr. 02, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Misconfiguration
-
1.7
LOWCVE-2006-6655
The procfs implementation in NetBSD-current before 20061023, NetBSD 3.0 and 3.0.1 before 20061024, and NetBSD 2.x before 20061029 allows local users to cause a denial of service (kernel panic) by attempting to access /emul/linux/proc/0/stat on a procfs fi... Read more
Affected Products : netbsd- EPSS Score: %0.06
- Published: Dec. 20, 2006
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2016-0405
Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4 allows local users to affect confidentiality via vectors related to Cluster Manageability and Serviceability.... Read more
- EPSS Score: %0.14
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.7
LOWCVE-2009-3401
Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows local users to affect confidentiality via unknown vectors.... Read more
Affected Products : e-business_suite- EPSS Score: %0.23
- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2015-1009
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.... Read more
- EPSS Score: %0.11
- Published: Aug. 01, 2015
- Modified: Apr. 12, 2025
-
1.7
LOWCVE-2011-1820
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.... Read more
Affected Products : tivoli_directory_server- EPSS Score: %0.07
- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2006-4642
AuditWizard 6.3.2, when using "Remote Audit," logs the administrator password in plaintext to LaytonCmdSvc.log, which allows local users to obtain sensitive information by reading the file.... Read more
Affected Products : auditwizard- EPSS Score: %0.07
- Published: Sep. 08, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2005-2993
Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang).... Read more
- EPSS Score: %0.18
- Published: Sep. 20, 2005
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2008-1754
Symantec Altiris Deployment Solution before 6.9.164 stores the Deployment Solution Agent (aka AClient) password in cleartext in memory, which allows local users to obtain sensitive information by dumping the AClient.exe process memory.... Read more
Affected Products : altiris_deployment_solution- EPSS Score: %0.08
- Published: Apr. 11, 2008
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2011-2312
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, related to ZFS.... Read more
Affected Products : solaris- EPSS Score: %0.15
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2009-1990
Unspecified vulnerability in the Business Intelligence Enterprise Edition component in Oracle Application Server 10.1.3.4.1 allows local users to affect confidentiality via unknown vectors.... Read more
Affected Products : application_server- EPSS Score: %0.11
- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2008-2619
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Application Server 1.0.2.2, 9.0.4.3, and 10.1.2.2, and E-Business Suite 11.5.10.2, allows remote authenticated users to affect availability via unknown vectors.... Read more
- EPSS Score: %0.36
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2025-43863
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password ... Read more
Affected Products : vantage6- Published: Jun. 12, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authentication
-
1.7
LOWCVE-2011-2291
Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality via unknown vectors related to Trusted Extensions.... Read more
- EPSS Score: %0.06
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2006-0391
Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper.... Read more
Affected Products : mac_os_x- EPSS Score: %0.63
- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2012-0494
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows local users to affect availability via unknown vectors.... Read more
Affected Products : mysql- EPSS Score: %0.06
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2007-0287
Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08.... Read more
- EPSS Score: %0.37
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2007-0288
Unspecified vulnerability in Oracle Application Server 10.1.4.0 has unknown impact and attack vectors related to Oracle Internet Directory, aka OID01.... Read more
Affected Products : application_server- EPSS Score: %0.37
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025