Latest CVE Feed
-
2.6
LOWCVE-2006-3484
Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) admin/create_course.php, show_courses parameter to (b) u... Read more
Affected Products : atutor- EPSS Score: %1.15
- Published: Jul. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3680
Cross-site scripting (XSS) vulnerability in photocycle in Photocycle 1.0 allows remote attackers to inject arbitrary web script or HTML via the phpage parameter.... Read more
Affected Products : photocycle- EPSS Score: %0.95
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3729
DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object, whi... Read more
- EPSS Score: %22.29
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2414
Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, ... Read more
Affected Products : xpcom- EPSS Score: %5.00
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3795
Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before 1.08 allow remote attackers to inject arbitrary web script or HTML via the (1) membercookie cookie in header.php and the (2) redirect parameter in misc.php.... Read more
Affected Products : deluxebb- EPSS Score: %0.56
- Published: Jul. 24, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5800
Cross-site scripting (XSS) vulnerability in default.asp in xenis.creator CMS allows remote attackers to inject arbitrary web script or HTML via the nav parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from t... Read more
Affected Products : xenis.creator_cms- EPSS Score: %0.29
- Published: Nov. 08, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1817
SQL injection vulnerability in authcheck.php in warforge.NEWS 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) authusername and possibly the (2) authpassword cookie.... Read more
Affected Products : warforge.news- EPSS Score: %0.50
- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3848
Cross-site scripting (XSS) vulnerability in CGI wrapper for IP Calculator (IPCalc) 0.40 allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI environment variable), which is used in the actionurl variable.... Read more
Affected Products : ip_calculator- EPSS Score: %0.80
- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-7139
Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or ... Read more
- EPSS Score: %8.16
- Published: Mar. 07, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-0641
Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a potential privacy leak that might allow transmission of... Read more
Affected Products : undercover- EPSS Score: %0.34
- Published: Feb. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0704
iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error messa... Read more
Affected Products : ie_integrator- EPSS Score: %0.39
- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1806
Cross-site scripting (XSS) vulnerability in index.php in Musicbox 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter in a search action.... Read more
Affected Products : musicbox- EPSS Score: %0.53
- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0724
profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new... Read more
Affected Products : magic_news_lite- EPSS Score: %0.73
- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0722
settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) ne... Read more
Affected Products : magic_downloads- EPSS Score: %0.90
- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-2083
Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."... Read more
Affected Products : opera_browser- EPSS Score: %1.14
- Published: Feb. 11, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-1536
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a ser... Read more
- EPSS Score: %52.48
- Published: Aug. 12, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-1489
Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.... Read more
Affected Products : opera_browser- EPSS Score: %0.41
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-1772
Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the... Read more
- EPSS Score: %59.44
- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-0433
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash)... Read more
Affected Products : websphere_application_server- EPSS Score: %0.71
- Published: Feb. 10, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-5143
McAfee VirusScan Enterprise before 8.8 allows local users to disable the product by leveraging administrative privileges to execute an unspecified Metasploit Framework module.... Read more
Affected Products : virusscan_enterprise- EPSS Score: %0.05
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025