Latest CVE Feed
-
2.6
LOWCVE-2006-0208
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are includ... Read more
Affected Products : php- EPSS Score: %3.29
- Published: Jan. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2014-6585
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to 2D, a different vulnerability than CVE-2014-6591.... Read more
- EPSS Score: %1.91
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2013-5679
The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attacker... Read more
Affected Products : enterprise_security_api- EPSS Score: %0.10
- Published: Sep. 30, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2022-3521
A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition. It is recommended to apply a pa... Read more
- EPSS Score: %0.03
- Published: Oct. 16, 2022
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2008-5460
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect confidentiality via unknown vectors.... Read more
Affected Products : bea_product_suite- EPSS Score: %0.33
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-3962
The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunisti... Read more
Affected Products : ssmtp- EPSS Score: %0.61
- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2011-3872
Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to the X.509 Subject Alternative Name field of the certific... Read more
- EPSS Score: %2.78
- Published: Oct. 27, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-0800
Interpretation conflict in PostNuke 0.761 and earlier allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML tags with a trailing "<" character, which is interpreted as a ">" character by some web browsers but bypasses the blacklis... Read more
Affected Products : postnuke- EPSS Score: %7.48
- Published: Feb. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2014-4208
Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4220.... Read more
- EPSS Score: %2.09
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2013-4505
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL... Read more
- EPSS Score: %1.79
- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-4914
Directory traversal vulnerability in A.l-Pifou 1.8p2 allows remote attackers to read arbitrary files via ".." sequences in the ze_langue_02 cookie, as demonstrated by using the choix_lng parameter to choix_langue.php to indirectly set the cookie, then acc... Read more
Affected Products : a.l-pifou- EPSS Score: %0.84
- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-1693
Unspecified vulnerability in Oracle SPARC Enterprise M Series Servers XCP 1110 allows remote attackers to affect availability, related to XSCF Control Package (XCP).... Read more
- EPSS Score: %0.92
- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2004-1490
Opera 7.54 and earlier allows remote attackers to spoof file types in the download dialog via dots and non-breaking spaces (ASCII character code 160) in the (1) Content-Disposition or (2) Content-Type headers.... Read more
Affected Products : opera_browser- EPSS Score: %1.13
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-3427
The Data Security component in Apple iOS before 5 and Apple TV before 4.4 does not properly restrict use of the MD5 hash algorithm within X.509 certificates, which makes it easier for man-in-the-middle attackers to spoof servers or obtain sensitive inform... Read more
- EPSS Score: %0.31
- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-3218
The "Save for Web" selection in QuickTime Player in Apple Mac OS X through 10.6.8 exports HTML documents that contain an http link to a script file, which allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks by spoofing the htt... Read more
- EPSS Score: %0.66
- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-2694
Cross-site scripting (XSS) vulnerability in the chg_passwd function in web/swat.c in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allows remote authenticated administrators to inject arbitrary web script or HTML via the username par... Read more
- EPSS Score: %3.38
- Published: Jul. 29, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-4071
Cross-site scripting (XSS) vulnerability in AgentTicketZoom in OTRS 2.4.x before 2.4.9, when RichText is enabled, allows remote attackers to inject arbitrary web script or HTML via JavaScript in an HTML e-mail.... Read more
Affected Products : otrs- EPSS Score: %0.44
- Published: Jan. 20, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-0244
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving u... Read more
Affected Products : drupal- EPSS Score: %0.41
- Published: Jan. 19, 2014
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-3560
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %3.51
- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-4022
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache ... Read more
Affected Products : bind- EPSS Score: %20.04
- Published: Nov. 25, 2009
- Modified: Apr. 09, 2025