Latest CVE Feed
-
2.6
LOWCVE-2008-0179
Cross-site scripting (XSS) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, which is used when composing Forgot Password e-mail m... Read more
Affected Products : liferay_enterprise_portal- EPSS Score: %3.87
- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-3838
Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this... Read more
Affected Products : dr- EPSS Score: %1.48
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-3685
Cross-site scripting (XSS) vulnerability in rpc.php in Unobtrusive Ajax Star Rating Bar before 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : unobtrusive_ajax_star_rating_bar- EPSS Score: %0.36
- Published: Jul. 11, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2001-0091
The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.... Read more
Affected Products : internet_explorer- EPSS Score: %13.45
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-3835
Cross-site scripting (XSS) vulnerability in Ex Libris MetaLib 3.13 and 4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a resource id that can be discovered through a search.... Read more
Affected Products : metalib- EPSS Score: %0.50
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2002-0284
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.... Read more
Affected Products : winamp- EPSS Score: %0.45
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-5847
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.... Read more
Affected Products : constructr-cms- EPSS Score: %1.52
- Published: Jan. 05, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1712
Cross-site scripting (XSS) vulnerability in the private archive script (private.py) in GNU Mailman 2.1.7 allows remote attackers to inject arbitrary web script or HTML via the action argument.... Read more
Affected Products : mailman- EPSS Score: %0.56
- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3738
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content... Read more
Affected Products : mambo_site_server- EPSS Score: %7.52
- Published: Nov. 22, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1182
Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web servi... Read more
- EPSS Score: %0.24
- Published: Mar. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1788
Adobe Document Server for Reader Extensions 6.0, during log on, provides different error messages depending on whether the user ID is valid or invalid, which allows remote attackers to more easily identify valid user IDs via brute force attacks.... Read more
Affected Products : document_server- EPSS Score: %2.14
- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-6677
ESET NOD32 Antivirus before 1.1743 allows remote attackers to cause a denial of service (crash) via a crafted .CHM file that triggers a divide-by-zero error.... Read more
- EPSS Score: %1.06
- Published: Dec. 21, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-0802
Cross-site scripting (XSS) vulnerability in the NS-Languages module for PostNuke 0.761 and earlier, when magic_quotes_gpc is enabled, allows remote attackers to inject arbitrary web script or HTML via the language parameter in a missing or translation ope... Read more
Affected Products : postnuke- EPSS Score: %0.53
- Published: Feb. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-0433
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash)... Read more
Affected Products : websphere_application_server- EPSS Score: %0.71
- Published: Feb. 10, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-1877
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently revea... Read more
- EPSS Score: %0.82
- Published: Mar. 30, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-5710
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.... Read more
Affected Products : wordpress- EPSS Score: %3.13
- Published: Oct. 30, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1064
Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : lurker- EPSS Score: %0.87
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5578
Microsoft Internet Explorer 6 and earlier allows remote attackers to read Temporary Internet Files (TIF) and obtain sensitive information via unspecified vectors involving certain drag and drop operations, aka "TIF Folder Information Disclosure Vulnerabil... Read more
Affected Products : ie- EPSS Score: %47.87
- Published: Dec. 12, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2002-0422
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 20... Read more
Affected Products : internet_information_services- EPSS Score: %48.52
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5791
Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the filename for downloading, which is not quoted in an error message by the send_file_direct fu... Read more
Affected Products : elog_web_logbook- EPSS Score: %0.54
- Published: Nov. 07, 2006
- Modified: Apr. 09, 2025