Latest CVE Feed
-
2.6
LOWCVE-2006-5455
Cross-site request forgery (CSRF) vulnerability in editversions.cgi in Bugzilla before 2.22.1 and 2.23.x before 2.23.3 allows user-assisted remote attackers to create, modify, or delete arbitrary bug reports via a crafted URL.... Read more
Affected Products : bugzilla- EPSS Score: %0.91
- Published: Oct. 23, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-0452
Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink at... Read more
Affected Products : perl- EPSS Score: %0.05
- Published: Dec. 21, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-3649
Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, ... Read more
- EPSS Score: %0.26
- Published: Nov. 09, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-5229
OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses take longer for valid usernames than... Read more
- EPSS Score: %38.14
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2011-3266
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE ... Read more
Affected Products : wireshark- EPSS Score: %1.02
- Published: Aug. 24, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-4807
loader_tga.c in imlib2 before 1.2.1, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted TGA image that triggers an out-of-bounds memory read, a different issue than CVE-2006-4808.... Read more
Affected Products : imlib2- EPSS Score: %2.14
- Published: Nov. 07, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-3174
Cross-site scripting (XSS) vulnerability in search.php in SquirrelMail 1.5.1 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary HTML via the mailbox parameter.... Read more
Affected Products : squirrelmail- EPSS Score: %1.16
- Published: Jun. 23, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4390
CFNetwork in Apple Mac OS X 10.4 through 10.4.7 and 10.3.9 allows remote SSL sites to appear as trusted sites by using encryption without authentication, which can cause the lock icon in Safari to be displayed even when the site's identity cannot be trust... Read more
Affected Products : mac_os_x- EPSS Score: %0.28
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-3862
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 throug... Read more
Affected Products : jboss_enterprise_application_platform jboss_enterprise_web_platform jboss_remoting- EPSS Score: %1.39
- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-3672
KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero... Read more
Affected Products : konqueror- EPSS Score: %5.62
- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5793
The sPLT chunk handling code (png_set_sPLT function in pngset.c) in libpng 1.0.6 through 1.2.12 uses a sizeof operator on the wrong data type, which allows context-dependent attackers to cause a denial of service (crash) via malformed sPLT chunks that tri... Read more
Affected Products : libpng- EPSS Score: %2.33
- Published: Nov. 17, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-4584
Opera before 11.00, when Opera Turbo is used, does not properly present information about problematic X.509 certificates on https web sites, which might make it easier for remote attackers to spoof trusted content via a crafted web site.... Read more
Affected Products : opera_browser- EPSS Score: %0.18
- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-2786
HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (... Read more
- EPSS Score: %2.44
- Published: Jun. 02, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-0169
WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripti... Read more
- EPSS Score: %0.36
- Published: Mar. 11, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2003-0282
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.... Read more
- EPSS Score: %12.23
- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2010-4583
Opera before 11.00, when Opera Turbo is enabled, does not display a page's security indication, which makes it easier for remote attackers to spoof trusted content via a crafted web site.... Read more
Affected Products : opera_browser- EPSS Score: %0.33
- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-2788
Cross-site scripting (XSS) vulnerability in profileinfo.php in MediaWiki before 1.15.5, when wgEnableProfileInfo is enabled, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.... Read more
Affected Products : mediawiki- EPSS Score: %0.66
- Published: Apr. 27, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2014-4440
The MCX Desktop Config Profiles implementation in Apple OS X before 10.10 retains web-proxy settings from uninstalled mobile-configuration profiles, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging... Read more
- EPSS Score: %0.84
- Published: Oct. 18, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-2476
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 supports SSL 2.0, which makes it easier for remote attackers to defea... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- EPSS Score: %27.10
- Published: Aug. 15, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-2047
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty value.... Read more
- EPSS Score: %0.77
- Published: Feb. 23, 2015
- Modified: Apr. 12, 2025