Latest CVE Feed
-
2.6
LOWCVE-2008-0994
Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods.... Read more
- EPSS Score: %0.35
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-3622
Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed messages.... Read more
Affected Products : mdaemon- EPSS Score: %1.05
- Published: Jul. 09, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-0274
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.... Read more
Affected Products : drupal- EPSS Score: %0.65
- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1064
Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : lurker- EPSS Score: %0.87
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-2083
Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."... Read more
Affected Products : opera_browser- EPSS Score: %1.14
- Published: Feb. 11, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0802
Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled, allows remote attackers to inject arbitrary web script or HTML via the language parameter in a missing or translation ope... Read more
Affected Products : postnuke- EPSS Score: %0.53
- Published: Feb. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2517
Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site.... Read more
- EPSS Score: %0.30
- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4673
Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.... Read more
- EPSS Score: %0.60
- Published: Sep. 11, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-2491
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, whic... Read more
Affected Products : opera_browser- EPSS Score: %10.39
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4650
Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memor... Read more
Affected Products : ios- EPSS Score: %0.49
- Published: Sep. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1790
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismat... Read more
Affected Products : internet_explorer- EPSS Score: %84.75
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4527
includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which allows remote attackers to conduct PHP remote file inclusion... Read more
Affected Products : cubecart- EPSS Score: %0.46
- Published: Sep. 01, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-0433
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash)... Read more
Affected Products : websphere_application_server- EPSS Score: %0.71
- Published: Feb. 10, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-0388
Safari in Mac OS X 10.3 before 10.3.9 and 10.4 before 10.4.5 allows remote attackers to redirect users to local files and execute arbitrary JavaScript via unspecified vectors involving HTTP redirection to local resources.... Read more
- EPSS Score: %0.41
- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5791
Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the filename for downloading, which is not quoted in an error message by the send_file_direct fu... Read more
Affected Products : elog_web_logbook- EPSS Score: %0.54
- Published: Nov. 07, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2025-25985
An issue in Macro-video Technologies Co.,Ltd V380E6_C1 IP camera (Hw_HsAKPIQp_WF_XHR) 1020302 allows a physically proximate attacker to execute arbitrary code via the /mnt/mtd/mvconf/wifi.ini and /mnt/mtd/mvconf/user_info.ini components.... Read more
- Published: Apr. 18, 2025
- Modified: Jun. 25, 2025
- Vuln Type: Authentication
-
2.6
LOWCVE-2013-5803
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availabil... Read more
- EPSS Score: %2.85
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2025-46570
vLLM is an inference and serving engine for large language models (LLMs). Prior to version 0.9.0, when a new prompt is processed, if the PageAttention mechanism finds a matching prefix chunk, the prefill process speeds up, which is reflected in the TTFT (... Read more
Affected Products : vllm- Published: May. 29, 2025
- Modified: Jun. 24, 2025
- Vuln Type: Information Disclosure
-
2.6
LOWCVE-2025-48938
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands... Read more
Affected Products :- Published: May. 30, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Path Traversal
-
2.6
LOWCVE-2005-1918
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably inv... Read more
- EPSS Score: %2.06
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025