Latest CVE Feed
-
2.6
LOWCVE-2006-6483
Adobe ColdFusion MX 7.x before 7.0.2 does not properly filter HTML tags when protecting against cross-site scripting (XSS) attacks, which allows remote attackers to inject arbitrary web script or HTML via a NULL byte (%00) in certain HTML tags, as demonst... Read more
Affected Products : coldfusion- EPSS Score: %2.00
- Published: Dec. 12, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-2933
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involvi... Read more
Affected Products : firefox- EPSS Score: %7.09
- Published: Jul. 17, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-0837
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.... Read more
- EPSS Score: %2.36
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1721
digestmd5.c in the CMU Cyrus Simple Authentication and Security Layer (SASL) library 2.1.18, and possibly other versions before 2.1.21, allows remote unauthenticated attackers to cause a denial of service (segmentation fault) via malformed inputs in DIGES... Read more
Affected Products : sasl- EPSS Score: %3.61
- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-4456
ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by levera... Read more
Affected Products : owncloud_desktop_client- EPSS Score: %0.16
- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2010-4472
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier allows remote attackers to affect availability, related to XML Digital Signature and unspecified APIs. NOTE: the previous info... Read more
- EPSS Score: %8.00
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-1945
The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easi... Read more
Affected Products : openssl- EPSS Score: %4.94
- Published: May. 31, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2007-0286
Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07.... Read more
- EPSS Score: %0.65
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-2431
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.... Read more
Affected Products : cups- EPSS Score: %0.03
- Published: Jun. 22, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-1192
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another s... Read more
- EPSS Score: %30.14
- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4685
The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.... Read more
- EPSS Score: %55.39
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-2832
Cross-site scripting (XSS) vulnerability in the upload module (upload.module) in Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2 allows remote attackers to inject arbitrary web script or HTML via the uploaded filename.... Read more
Affected Products : drupal- EPSS Score: %0.53
- Published: Jun. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4144
Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, whi... Read more
Affected Products : imagemagick- EPSS Score: %22.22
- Published: Aug. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2014-3886
Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.... Read more
Affected Products : webmin- EPSS Score: %0.25
- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2007-0895
Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it... Read more
- EPSS Score: %0.07
- Published: Feb. 13, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-0537
The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a c... Read more
Affected Products : konqueror- EPSS Score: %1.73
- Published: Jan. 29, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-2509
CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.... Read more
Affected Products : php- EPSS Score: %3.93
- Published: May. 09, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1908
Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third... Read more
Affected Products : myevent- EPSS Score: %0.35
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1045
The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive informati... Read more
Affected Products : thunderbird- EPSS Score: %10.40
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3007
Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with a trailing "." (dot), which might allow remote attackers to trick users into processing dangerous content.... Read more
Affected Products : opera_browser- EPSS Score: %1.45
- Published: Sep. 21, 2005
- Modified: Apr. 03, 2025