{"api_version":"1","generated_at":"2026-05-10T07:09:04+00:00","cve":"CVE-2006-6286","urls":{"html":"https://cve.report/CVE-2006-6286","api":"https://cve.report/api/cve/CVE-2006-6286.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6286","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6286"},"summary":{"title":"CVE-2006-6286","description":"Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, which allows local users to obtain sensitive information (address books, calendar files, and todo lists of other users) via unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-12-04 11:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"1.7","severity":"","vector":"AV:L/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30657","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30657","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21382/info","name":"http://www.securityfocus.com/bid/21382/info","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Palm Desktop Application Directory Local Insecure Permissions Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/4803","name":"http://www.vupen.com/english/advisories/2006/4803","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23072","name":"http://secunia.com/advisories/23072","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Palm Desktop Software Insecure Permissions - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21382","name":"BID:21382","refsource":"MITRE","tags":[],"title":"Palm Desktop Application Directory Local Insecure Permissions Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6286","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6286","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6286","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"palm","cpe5":"palm_desktop","cpe6":"4.0b76","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6286","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"palm","cpe5":"palm_desktop","cpe6":"4.0b77","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6286","vulnerable":"1","versionEndIncluding":"4.1.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"palm","cpe5":"palm_desktop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:19:35.208Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"palmdesktop-files-insecure-permission(30657)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30657"},{"name":"23072","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23072"},{"name":"ADV-2006-4803","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4803"},{"name":"21382","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21382/info"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-12-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, which allows local users to obtain sensitive information (address books, calendar files, and todo lists of other users) via unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"palmdesktop-files-insecure-permission(30657)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30657"},{"name":"23072","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23072"},{"name":"ADV-2006-4803","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4803"},{"name":"21382","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21382/info"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6286","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, which allows local users to obtain sensitive information (address books, calendar files, and todo lists of other users) via unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"palmdesktop-files-insecure-permission(30657)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30657"},{"name":"23072","refsource":"SECUNIA","url":"http://secunia.com/advisories/23072"},{"name":"ADV-2006-4803","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4803"},{"name":"21382","refsource":"BID","url":"http://www.securityfocus.com/bid/21382/info"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6286","datePublished":"2006-12-04T11:00:00.000Z","dateReserved":"2006-12-04T00:00:00.000Z","dateUpdated":"2024-08-07T20:19:35.208Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-04 11:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:S/C:P/I:N/A:N","baseScore":1.7,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.1,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:palm:palm_desktop:*:*:*:*:*:*:*:*","versionEndIncluding":"4.1.4","matchCriteriaId":"3F5404FD-B98A-4CEA-B14A-5011AF485714"},{"vulnerable":true,"criteria":"cpe:2.3:a:palm:palm_desktop:4.0b76:*:*:*:*:*:*:*","matchCriteriaId":"0999067A-2A2B-42BB-9C15-050BA0105CDC"},{"vulnerable":true,"criteria":"cpe:2.3:a:palm:palm_desktop:4.0b77:*:*:*:*:*:*:*","matchCriteriaId":"4B882DC2-2672-4243-A8C1-61BFC548DAD9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6286","Ordinal":"1","Title":"CVE-2006-6286","CVE":"CVE-2006-6286","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6286","Ordinal":"1","NoteData":"Palm Desktop 4.1.4 and earlier stores user data with weak permissions under the application directory, which allows local users to obtain sensitive information (address books, calendar files, and todo lists of other users) via unspecified vectors.  NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.","Type":"Description","Title":"CVE-2006-6286"},{"CveYear":"2006","CveId":"6286","Ordinal":"2","NoteData":"2006-12-04","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6286","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}