Latest CVE Feed
-
2.6
LOWCVE-2006-3071
Cross-site scripting (XSS) vulnerability in index.php in MP3 Search/Archive 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter, as used by the "search box", and (2) res parameter.... Read more
Affected Products : mp3_search_archive- EPSS Score: %0.53
- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-4998
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-019 and 4.0.2.x before 4.0.2.7-P8AE-FP007, in certain FileTracker configurations, does not apply a security policy to the first document added during a session... Read more
Affected Products : filenet_p8_application_engine- EPSS Score: %0.16
- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2000-0028
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.... Read more
- EPSS Score: %21.84
- Published: Dec. 23, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2648
Cross-site scripting (XSS) vulnerability in perform_search.asp for ASPBB 0.52 and earlier allows remote attackers to inject arbitrary HTML or web script via the search parameter.... Read more
Affected Products : aspbb- EPSS Score: %7.01
- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1791
Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address. NOTE: if there is not an exploit scenar... Read more
Affected Products : ie- EPSS Score: %9.40
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0871
Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.... Read more
Affected Products : internet_explorer- EPSS Score: %11.22
- Published: Sep. 04, 1998
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2018-0942
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow elevation of privilege, due to how Interne... Read more
- EPSS Score: %1.25
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2004-0837
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.... Read more
- EPSS Score: %2.36
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-2947
chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1, when a certain mohinterpret setting is enabled, allows remote attackers to cause a denial o... Read more
- EPSS Score: %4.30
- Published: Jun. 02, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2005-1049
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could... Read more
Affected Products : postnuke- EPSS Score: %13.24
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-3216
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown ... Read more
- EPSS Score: %2.07
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-4265
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 throug... Read more
Affected Products : jboss_enterprise_application_platform jboss_enterprise_web_platform jboss_remoting- EPSS Score: %1.03
- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2004-2014
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.... Read more
Affected Products : wget- EPSS Score: %0.12
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-4456
ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by levera... Read more
Affected Products : owncloud_desktop_client- EPSS Score: %0.16
- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2008-2933
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involvi... Read more
Affected Products : firefox- EPSS Score: %7.09
- Published: Jul. 17, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2005-0232
Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen... Read more
Affected Products : firefox- EPSS Score: %1.32
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1801
The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.... Read more
Affected Products : 9500- EPSS Score: %2.84
- Published: May. 26, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-2492
Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.... Read more
- EPSS Score: %0.36
- Published: Jul. 17, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-2547
NetWin (1) SurgeMail before 2.0c and (2) WebMail allow remote attackers to obtain sensitive information via HTTP requests that (a) specify the / URI, (b) specify the /scripts/ URI, or (c) specify a non-existent file, which reveal the path in an error mess... Read more
- EPSS Score: %16.00
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1673
Cross-site scripting (XSS) vulnerability in vbugs.php in Dark_Wizard vBug Tracker 3.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter.... Read more
Affected Products : vbug_tracker- EPSS Score: %0.68
- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025