Latest CVE Feed
-
2.6
LOWCVE-2004-1324
The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.... Read more
- EPSS Score: %16.72
- Published: Dec. 18, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-2530
Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files via a filename with a large number of spaces followed by the real extension, which is not displayed in the dialog box.... Read more
Affected Products : gadu-gadu_instant_messenger- EPSS Score: %5.78
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-2717
Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2) What parameters.... Read more
Affected Products : phpmychat- EPSS Score: %2.24
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1495
The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.... Read more
Affected Products : winrar- EPSS Score: %0.91
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1347
** UNVERIFIABLE ** NOTE: this issue describes a problem that can not be independently verified as of 20050421. Adobe Acrobat reader (AcroRd32.exe) 6.0 and earlier allows remote attackers to cause a denial of service ("Invalid-ID-Handle-Error" error) and... Read more
Affected Products : acrobat_reader- EPSS Score: %8.23
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-1903
Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web script or HTML via the part parameter.... Read more
Affected Products : sonicbb- EPSS Score: %1.06
- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-3835
Cross-site scripting (XSS) vulnerability in Ex Libris MetaLib 3.13 and 4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a resource id that can be discovered through a search.... Read more
Affected Products : metalib- EPSS Score: %0.50
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-3838
Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this... Read more
Affected Products : dr- EPSS Score: %1.48
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-4679
CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force clients to connect to other hosts via crafted responses to FTP PASV commands.... Read more
Affected Products : mac_os_x- EPSS Score: %0.71
- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2005-0145
Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.... Read more
Affected Products : firefox- EPSS Score: %1.03
- Published: Jan. 24, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0143
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.... Read more
- EPSS Score: %0.77
- Published: Mar. 23, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1967
Cross-site scripting (XSS) vulnerability in calendar/Visitor.cgi in KCScripts Calendar, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the sort_order parameter.... Read more
- EPSS Score: %0.53
- Published: Apr. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2653
Cross-site scripting (XSS) vulnerability in login_error.shtml for D-Link DSA-3100 allows remote attackers to inject arbitrary HTML or web script via an encoded uname parameter.... Read more
Affected Products : dsa-3100_airspot_gateway- EPSS Score: %0.70
- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2163
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter.... Read more
Affected Products : pinnacle_cart- EPSS Score: %0.51
- Published: May. 04, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2165
Multiple cross-site scripting (XSS) vulnerabilities in Avactis Shopping Cart 0.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category_id parameter in (a) store_special_offers.php and (b) store.php and (2) prod_i... Read more
Affected Products : avactis_shopping_cart- EPSS Score: %0.36
- Published: May. 04, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-7412
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain... Read more
Affected Products : datapower_gateway- EPSS Score: %0.21
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-0595
/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the gran... Read more
- EPSS Score: %0.12
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2013-7078
Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in the Extbase Framework in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6, when the Rewritten Property ... Read more
Affected Products : typo3- EPSS Score: %0.49
- Published: Jan. 19, 2014
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-5951
Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_... Read more
Affected Products : extplorer- EPSS Score: %0.32
- Published: Mar. 25, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-2476
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 supports SSL 2.0, which makes it easier for remote attackers to defea... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- EPSS Score: %27.10
- Published: Aug. 15, 2015
- Modified: Apr. 12, 2025