Latest CVE Feed
-
2.6
LOWCVE-1999-1009
The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.... Read more
Affected Products : go_express_search- EPSS Score: %0.35
- Published: Dec. 12, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-5847
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.... Read more
Affected Products : constructr-cms- EPSS Score: %1.52
- Published: Jan. 05, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-2151
Cross-site request forgery (CSRF) vulnerability in Fujitsu e-Pares V01 L01 V01 L01, L03, L10, L20, L30, and L40 allows remote attackers to hijack the authentication of users for requests that modify "facility reservation data" via unknown vectors.... Read more
Affected Products : e-pares- EPSS Score: %0.12
- Published: Jun. 03, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-4739
Multiple cross-site scripting (XSS) vulnerabilities in Jetbox CMS allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the OriginalImageData parameter to phpthumb.php.... Read more
Affected Products : jetbox_cms- EPSS Score: %0.33
- Published: Sep. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3402
The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection vi... Read more
Affected Products : thunderbird- EPSS Score: %0.29
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4726
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 6.1 through 7.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving a ColdFusion error page.... Read more
Affected Products : coldfusion- EPSS Score: %2.04
- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4210
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these deta... Read more
Affected Products : phpay- EPSS Score: %5.90
- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1331
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.... Read more
- EPSS Score: %27.11
- Published: Nov. 16, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-0685
Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow... Read more
- EPSS Score: %21.74
- Published: Feb. 03, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-3820
konqueror/konq_combo.cc in Konqueror 3.5.7 allows remote attackers to spoof the data: URI scheme in the address bar via a long URI with trailing whitespace, which prevents the beginning of the URI from being displayed.... Read more
Affected Products : konqueror- EPSS Score: %1.06
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-4679
CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force clients to connect to other hosts via crafted responses to FTP PASV commands.... Read more
Affected Products : mac_os_x- EPSS Score: %0.71
- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-3622
Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed messages.... Read more
Affected Products : mdaemon- EPSS Score: %1.05
- Published: Jul. 09, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1786
Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op parameter in AlterCast. NOTE: it is n... Read more
Affected Products : document_server- EPSS Score: %5.47
- Published: Apr. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-3807
Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and other unspecified vectors.... Read more
Affected Products : sitescape_forum- EPSS Score: %0.48
- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-5710
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.... Read more
Affected Products : wordpress- EPSS Score: %3.13
- Published: Oct. 30, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-3320
Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the command parameter.... Read more
Affected Products : sitebar- EPSS Score: %1.36
- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1489
Opera 7.54 and earlier does not properly limit an applet's access to internal Java packages from Sun, which allows remote attackers to gain sensitive information, such as user names and the installation directory.... Read more
Affected Products : opera_browser- EPSS Score: %0.41
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4527
includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which allows remote attackers to conduct PHP remote file inclusion... Read more
Affected Products : cubecart- EPSS Score: %0.46
- Published: Sep. 01, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3738
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content... Read more
Affected Products : mambo_site_server- EPSS Score: %7.52
- Published: Nov. 22, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2789
Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-add... Read more
Affected Products : evolution- EPSS Score: %0.79
- Published: Jun. 02, 2006
- Modified: Apr. 03, 2025