Latest CVE Feed
-
2.6
LOWCVE-2006-3278
Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) next_template, (2) start, (3) curr_menu_id, and (4) arid parameters in psoft/servlet/resadmin/psoft.hs... Read more
Affected Products : h-sphere- EPSS Score: %0.53
- Published: Jun. 28, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0519
Internet Explorer 4.x and 5.x does not properly re-validate an SSL certificate if the user establishes a new SSL session with the same server during the same Internet Explorer session, aka one of two different "SSL Certificate Validation" vulnerabilities.... Read more
- EPSS Score: %2.19
- Published: Jun. 05, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3313
Cross-site scripting (XSS) vulnerability in search.jsp in Netsoft smartNet 2.0 allows remote attackers to inject arbitrary web script or HTML via the keyWord parameter.... Read more
Affected Products : smartnet- EPSS Score: %0.67
- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-5460
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect confidentiality via unknown vectors.... Read more
Affected Products : bea_product_suite- EPSS Score: %0.33
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2013-4505
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL... Read more
- EPSS Score: %1.79
- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2014-0591
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exi... Read more
Affected Products : bind- EPSS Score: %43.55
- Published: Jan. 14, 2014
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2005-0231
Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."... Read more
Affected Products : firefox- EPSS Score: %2.66
- Published: Feb. 07, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2014-6591
Unspecified vulnerability in the Java SE component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6585.... Read more
- EPSS Score: %1.71
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2006-0800
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklis... Read more
Affected Products : postnuke- EPSS Score: %7.48
- Published: Feb. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2025-25183
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Maliciously constructed statements can lead to hash collisions, resulting in cache reuse, which can interfere with subsequent responses and cause unintended behavior. Pr... Read more
Affected Products : vllm- Published: Feb. 07, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Misconfiguration
-
2.6
LOWCVE-2010-0039
The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP a... Read more
- EPSS Score: %0.31
- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-5814
Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear wheth... Read more
Affected Products : php- EPSS Score: %1.02
- Published: Jan. 02, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-2311
Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1) .cfm or (2) .cfml file, which reflects the result in th... Read more
- EPSS Score: %0.44
- Published: Jun. 26, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1740
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the l... Read more
- EPSS Score: %2.19
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2002-1126
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, includin... Read more
- EPSS Score: %0.60
- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4567
Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting a mal... Read more
- EPSS Score: %1.86
- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1787
Adobe Document Server for Reader Extensions 6.0 includes a user's session (jsession) ID in the HTTP Referer header, which allows remote attackers to gain access to PDF files that are being processed within that session.... Read more
Affected Products : document_server- EPSS Score: %1.77
- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-5281
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the co... Read more
Affected Products : enterprise_linux- EPSS Score: %0.06
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2006-3812
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links.... Read more
- EPSS Score: %13.37
- Published: Jul. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0649
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.... Read more
- EPSS Score: %62.75
- Published: Jul. 13, 2000
- Modified: Apr. 03, 2025