Latest CVE Feed
-
1.7
LOWCVE-2004-2657
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list o... Read more
Affected Products : firefox- EPSS Score: %0.07
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2013-2382
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 12.0.1 allows local users to affect confidentiality via vectors related to BASE.... Read more
Affected Products : financial_services_software- EPSS Score: %0.15
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2007-0294
Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning & Data Guard Management, aka EM06.... Read more
Affected Products : enterprise_manager- EPSS Score: %0.37
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2003-0986
Various routines for the ppc64 architecture on Linux kernel 2.6 prior to 2.6.2 and 2.4 prior to 2.4.24 do not use the copy_from_user function when copying data from userspace to kernelspace, which crosses security boundaries and allows local users to caus... Read more
- EPSS Score: %0.06
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2014-2926
kapfa.sys in Kaseya Virtual System Administrator (VSA) 6.5 before 6.5.0.17 and 7.0 before 7.0.0.16 allows local users to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.... Read more
Affected Products : virtual_system_administrator- EPSS Score: %0.05
- Published: Jul. 14, 2014
- Modified: Apr. 12, 2025
-
1.7
LOWCVE-2025-43863
vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. If attacker gets access to an authenticated session, they can try to brute-force the user password ... Read more
Affected Products : vantage6- Published: Jun. 12, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authentication
-
1.7
LOWCVE-2013-1499
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Network Configuration.... Read more
- EPSS Score: %0.05
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2025-30218
Next.js is a React framework for building full-stack web applications. To mitigate CVE-2025-29927, Next.js validated the x-middleware-subrequest-id which persisted across multiple incoming requests. However, this subrequest ID is sent to all requests, eve... Read more
Affected Products : next.js- Published: Apr. 02, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Misconfiguration
-
1.7
LOWCVE-2006-1601
Unspecified vulnerability in SunPlex Manager in Sun Cluster 3.1 4/04 allows local users with solaris.cluster.gui authorization to view arbitrary files via unspecified vectors.... Read more
Affected Products : cluster- EPSS Score: %0.07
- Published: Apr. 04, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2006-6286
Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, which allows local users to obtain sensitive information (address books, calendar files, and todo lists of other users) via unspecified vectors. NOTE: ... Read more
Affected Products : palm_desktop- EPSS Score: %0.05
- Published: Dec. 04, 2006
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2006-0386
FileVault in Mac OS X 10.4.5 and earlier does not properly mount user directories when creating a FileVault image, which allows local users to access protected files when FileVault is enabled.... Read more
- EPSS Score: %0.07
- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2006-6510
An unspecified ActiveX control in SiteKiosk before 6.5.150 is installed "safe for scripting", which allows local users to bypass security protections and read arbitrary files via certain functions.... Read more
Affected Products : sitekiosk- EPSS Score: %0.08
- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2025-43866
vantage6 is an open-source infrastructure for privacy preserving analysis. The JWT secret key in the vantage6 server is auto-generated unless defined by the user. The auto-generated key is a UUID1, which is not cryptographically secure as it is predictabl... Read more
Affected Products : vantage6- Published: Jun. 12, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Cryptography
-
1.7
LOWCVE-2012-0494
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows local users to affect availability via unknown vectors.... Read more
Affected Products : mysql- EPSS Score: %0.06
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2015-0498
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors related to Replication.... Read more
Affected Products : mysql- EPSS Score: %0.39
- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
1.7
LOWCVE-2005-2993
Unspecified vulnerability in the FTP Daemon (ftpd) for HP Tru64 UNIX 4.0F PK8 and other versions up to HP Tru64 UNIX 5.1B-3, and HP-UX B.11.00, B.11.04, B.11.11, and B.11.23, allows remote authenticated users to cause a denial of service (hang).... Read more
- EPSS Score: %0.18
- Published: Sep. 20, 2005
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2007-0288
Unspecified vulnerability in Oracle Application Server 10.1.4.0 has unknown impact and attack vectors related to Oracle Internet Directory, aka OID01.... Read more
Affected Products : application_server- EPSS Score: %0.37
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2007-0287
Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08.... Read more
- EPSS Score: %0.37
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2007-3700
Sun Java System Access Manager (formerly Java System Identity Server) before 20070710, when the message debug level is configured in the com.iplanet.services.debug.level property in AMConfig.properties, logs cleartext login passwords, which allows local u... Read more
Affected Products : java_system_access_manager- EPSS Score: %0.06
- Published: Jul. 11, 2007
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2006-6107
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).... Read more
Affected Products : d-bus- EPSS Score: %0.10
- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025