Latest CVE Feed
-
1.5
LOWCVE-2014-5029
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537.... Read more
- EPSS Score: %0.05
- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
1.5
LOWCVE-2006-0678
PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a differen... Read more
Affected Products : postgresql- EPSS Score: %0.07
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
1.5
LOWCVE-2007-4126
Unspecified vulnerability in the dynamic tracing framework (DTrace) on Sun Solaris 10 before 20070730 allows local users with PRIV_DTRACE_USER privileges to cause a denial of service (panic or hang) via unspecified use of certain DTrace programs.... Read more
Affected Products : solaris- EPSS Score: %0.06
- Published: Aug. 01, 2007
- Modified: Apr. 09, 2025
-
1.5
LOWCVE-2015-4877
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more
Affected Products : fusion_middleware- EPSS Score: %0.27
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
1.5
LOWCVE-2015-0474
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.1, 8.5.0, and 8.5.1 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more
Affected Products : fusion_middleware- EPSS Score: %0.39
- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
1.5
LOWCVE-2012-3145
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 5.0.2, 5.0.5, 5.1.0, 5.2.0, 5.3.0 through 5.3.4, and 6.2.0 allows local users to affect confidentiality, related to BASE.... Read more
Affected Products : financial_services_software- EPSS Score: %0.32
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
1.5
LOWCVE-2015-4811
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via vectors related to Outside In PDF Export SDKutside In PDF Export SDK, a different vul... Read more
Affected Products : fusion_middleware- EPSS Score: %0.09
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
1.5
LOWCVE-2011-2318
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4.0, 10.0.2.0, 10.3.3.0, 10.3.4.0, and 10.3.5.0 allows local users to affect confidentiality, related to WLS Security.... Read more
- EPSS Score: %0.10
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
1.4
LOWCVE-2016-0618
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via unknown vectors related to Zones.... Read more
Affected Products : solaris- EPSS Score: %0.08
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.4
LOWCVE-2014-2485
Unspecified vulnerability in the Siebel Core - EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality via unknown vectors related to Integration Business Services.... Read more
Affected Products : siebel_crm- EPSS Score: %0.18
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
1.3
LOWCVE-2025-53903
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/users.js` doesn't properly sanitize text box inputs, leading to a potential vulnerability to cross-site scripting attacks. Commit 90b39eb56b27b2bac2... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cross-Site Scripting
-
1.3
LOWCVE-2015-5464
The Gemalto SafeNet Luna HSM allows remote authenticated users to bypass intended key-export restrictions by leveraging (1) crypto-user or (2) crypto-officer access to an HSM partition.... Read more
- EPSS Score: %0.06
- Published: Jul. 22, 2015
- Modified: Apr. 12, 2025
-
1.3
LOWCVE-2011-2242
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.1 and 11.2.0.2 allows local users to affect confidentiality, related to XML DB FTP.... Read more
Affected Products : database_server- EPSS Score: %0.30
- Published: Jul. 20, 2011
- Modified: Apr. 11, 2025
-
1.3
LOWCVE-2025-53374
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organiza... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
1.3
LOWCVE-2025-46826
insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal ri... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Information Disclosure
-
1.3
LOWCVE-2025-53904
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publication.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
1.2
LOWCVE-2007-3108
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.... Read more
Affected Products : openssl- EPSS Score: %0.10
- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
1.2
LOWCVE-2003-0462
A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).... Read more
Affected Products : linux_kernel mandrake_linux mandrake_linux_corporate_server mandrake_multi_network_firewall- EPSS Score: %0.16
- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-2666
SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user's account to generate a lis... Read more
Affected Products : openssh- EPSS Score: %0.15
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2007-0832
VMware Workstation 5.5.3 34685 does not immediately change the availability of a shared clipboard when the "Enable copy and paste to and from this virtual machine" checkbox is changed, which allows local users to obtain sensitive information or conduct ce... Read more
Affected Products : workstation- EPSS Score: %0.05
- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025