Latest CVE Feed
-
2.6
LOWCVE-2006-1833
Intel RNG Driver in NetBSD 1.6 through 3.0 may incorrectly detect the presence of the pchb interface, which will cause it to always generate the same random number, which allows remote attackers to more easily crack encryption keys generated from the inte... Read more
Affected Products : netbsd- EPSS Score: %0.32
- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1120
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in ... Read more
Affected Products : dcp-portal- EPSS Score: %1.45
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1801
The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.... Read more
Affected Products : 9500- EPSS Score: %2.84
- Published: May. 26, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5800
Cross-site scripting (XSS) vulnerability in default.asp in xenis.creator CMS allows remote attackers to inject arbitrary web script or HTML via the nav parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from t... Read more
Affected Products : xenis.creator_cms- EPSS Score: %0.29
- Published: Nov. 08, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-6068
Directory traversal vulnerability in the cached_album function in functions.php for mAlbum 0.3 and earlier allows remote attackers to list filenames of arbitrary images via a .. (dot dot) in the gal parameter to index.php.... Read more
Affected Products : malbum- EPSS Score: %0.64
- Published: Nov. 22, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-4259
Cross-site scripting (XSS) vulnerability in index.php in Fotopholder 1.8 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this might be resultant from a directory traversal vulnerability.... Read more
Affected Products : fotopholder- EPSS Score: %0.40
- Published: Aug. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0641
Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a potential privacy leak that might allow transmission of... Read more
Affected Products : undercover- EPSS Score: %0.34
- Published: Feb. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0704
iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error messa... Read more
Affected Products : ie_integrator- EPSS Score: %0.39
- Published: Feb. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0724
profile.php in Reamday Enterprises Magic News Lite 1.2.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new... Read more
Affected Products : magic_news_lite- EPSS Score: %0.73
- Published: Feb. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4726
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.... Read more
Affected Products : coldfusion- EPSS Score: %2.04
- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5404
Unspecified vulnerability in an ActiveX control used in Symantec Automated Support Assistant, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, allows user-assisted remote attackers to obtain sensitive information via unspeci... Read more
Affected Products : norton_system_works norton_antivirus norton_internet_security automated_support_assistant- EPSS Score: %0.71
- Published: Oct. 19, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1554
Cross-site scripting (XSS) vulnerability in VSNS Lemon 3.2.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter while adding a comment.... Read more
Affected Products : vsns_lemon- EPSS Score: %0.53
- Published: Mar. 31, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3038
Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Room Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this scri... Read more
Affected Products : realty_room_rent- EPSS Score: %0.50
- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3050
Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.... Read more
Affected Products : sixcms- EPSS Score: %5.60
- Published: Jun. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5432
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[f... Read more
Affected Products : phppowercards- EPSS Score: %9.39
- Published: Oct. 20, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-3044
Cross-site scripting (XSS) vulnerability in LogiSphere 1.6.0 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected in an error page.... Read more
Affected Products : logisphere- EPSS Score: %0.52
- Published: Jun. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1324
The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the Local computer zone via the (1) artist or (2) song fields of a music file, if the file is processed using Internet Explorer.... Read more
- EPSS Score: %16.72
- Published: Dec. 18, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-7139
Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service (crash) via an HTML e-mail with certain table and frameset tags that trigger a segmentation fault, possibly involving invalid free or ... Read more
- EPSS Score: %8.16
- Published: Mar. 07, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-0445
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to... Read more
Affected Products : client_security norton_internet_security norton_antispam norton_personal_firewall client_firewall- EPSS Score: %35.05
- Published: Jul. 07, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-1008
Apple iTunes 7.0.2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted XML list of radio stations, which results in memory corruption. NOTE: iTunes retrieves the XML document from a static URL, which requi... Read more
Affected Products : itunes- EPSS Score: %7.55
- Published: Feb. 20, 2007
- Modified: Apr. 09, 2025