Latest CVE Feed
-
2.6
LOWCVE-2014-6585
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6591.... Read more
- EPSS Score: %1.91
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-4208
Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4220.... Read more
- EPSS Score: %2.09
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2007-5238
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to ... Read more
- EPSS Score: %0.98
- Published: Oct. 06, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-5712
The internationalization (i18n) framework in Django 0.91, 0.95, 0.95.1, and 0.96, and as used in other products such as PyLucid, when the USE_I18N option and the i18n component are enabled, allows remote attackers to cause a denial of service (memory cons... Read more
- EPSS Score: %1.59
- Published: Oct. 30, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2009-0591
The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was... Read more
Affected Products : openssl- EPSS Score: %1.84
- Published: Mar. 27, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2005-1923
The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to ... Read more
Affected Products : clamav- EPSS Score: %0.66
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2025-25183
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Maliciously constructed statements can lead to hash collisions, resulting in cache reuse, which can interfere with subsequent responses and cause unintended behavior. Pr... Read more
Affected Products : vllm- Published: Feb. 07, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Misconfiguration
-
2.6
LOWCVE-2012-1253
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.... Read more
- EPSS Score: %0.25
- Published: Jun. 04, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-1164
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.... Read more
Affected Products : openldap- EPSS Score: %15.20
- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2015-1787
The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allows remote attackers to cause a denial of service (daemon crash) via a ClientKeyE... Read more
Affected Products : openssl- EPSS Score: %10.31
- Published: Mar. 19, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2013-0158
Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain ... Read more
- EPSS Score: %0.65
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-4775
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.9.2 and 3.0.1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the db parameter, a... Read more
Affected Products : phpmyadmin- EPSS Score: %7.23
- Published: Oct. 28, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2013-5679
The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attacker... Read more
Affected Products : enterprise_security_api- EPSS Score: %0.10
- Published: Sep. 30, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-0354
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors invol... Read more
Affected Products : firefox- EPSS Score: %0.58
- Published: Feb. 04, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2011-2694
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username par... Read more
- EPSS Score: %3.38
- Published: Jul. 29, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-0244
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving u... Read more
Affected Products : drupal- EPSS Score: %0.41
- Published: Jan. 19, 2014
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-4071
Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.... Read more
Affected Products : otrs- EPSS Score: %0.44
- Published: Jan. 20, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-0962
Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 6.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted content that is not properly handled during a copy-and-paste operation.... Read more
Affected Products : iphone_os- EPSS Score: %0.32
- Published: Jan. 29, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2018-1002102
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redire... Read more
- EPSS Score: %0.28
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2010-3560
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %3.51
- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025