Latest CVE Feed
-
2.6
LOWCVE-2012-1645
The CDN module 6.x-2.2 and 7.x-2.2 for Drupal, when running in Origin Pull mode with the "Far Future expiration" option enabled, allows remote attackers to read arbitrary PHP files via unspecified vectors, as demonstrated by reading settings.php.... Read more
- EPSS Score: %0.59
- Published: Aug. 28, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2005-0143
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.... Read more
- EPSS Score: %0.77
- Published: Mar. 23, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0145
Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.... Read more
Affected Products : firefox- EPSS Score: %1.03
- Published: Jan. 24, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3275
The NAT code (1) ip_nat_proto_tcp.c and (2) ip_nat_proto_udp.c in Linux kernel 2.6 before 2.6.13 and 2.4 before 2.4.32-rc1 incorrectly declares a variable to be static, which allows remote attackers to cause a denial of service (memory corruption) by caus... Read more
- EPSS Score: %8.97
- Published: Oct. 21, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2010-3560
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %3.51
- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-5137
IOKit in Apple iOS before 7 allows attackers to send user-interface events to the foreground app by leveraging control over a background app and using the (1) task-completion API or (2) VoIP API.... Read more
Affected Products : iphone_os- EPSS Score: %0.37
- Published: Sep. 19, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-3218
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the htt... Read more
- EPSS Score: %0.66
- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-4808
Heap-based buffer overflow in loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TGA image.... Read more
Affected Products : imlib2- EPSS Score: %4.59
- Published: Nov. 07, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-2833
Cross-site scripting (XSS) vulnerability in the taxonomy module in Drupal 4.6.8 and 4.7.2 allows remote attackers to inject arbitrary web script or HTML via inputs that are not properly validated when the page title is output, possibly involving the $name... Read more
Affected Products : drupal- EPSS Score: %1.01
- Published: Jun. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-3427
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive inform... Read more
- EPSS Score: %0.31
- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-4363
ProcessTable.pm in the Proc::ProcessTable module 0.45 for Perl, when TTY information caching is enabled, allows local users to overwrite arbitrary files via a symlink attack on /tmp/TTYDEVS.... Read more
- EPSS Score: %0.05
- Published: Oct. 07, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-4775
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a... Read more
Affected Products : phpmyadmin- EPSS Score: %7.23
- Published: Oct. 28, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2009-0354
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors invol... Read more
Affected Products : firefox- EPSS Score: %0.58
- Published: Feb. 04, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-2431
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.... Read more
Affected Products : cups- EPSS Score: %0.03
- Published: Jun. 22, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-4144
Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, whi... Read more
Affected Products : imagemagick- EPSS Score: %22.22
- Published: Aug. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-1058
Cross-site scripting (XSS) vulnerability in the reStructuredText (rst) parser in parser/text_rst.py in MoinMoin before 1.9.3, when docutils is installed or when "format rst" is set, allows remote attackers to inject arbitrary web script or HTML via a java... Read more
Affected Products : moinmoin- EPSS Score: %0.61
- Published: Feb. 22, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2016-3291
Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."... Read more
- EPSS Score: %5.16
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2012-2687
Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiViews option is enabled, allow remote attackers to inject ... Read more
Affected Products : http_server- EPSS Score: %5.02
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2007-1358
Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RF... Read more
Affected Products : tomcat- EPSS Score: %51.55
- Published: May. 10, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-1877
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently revea... Read more
- EPSS Score: %0.82
- Published: Mar. 30, 2004
- Modified: Apr. 03, 2025