Latest CVE Feed
-
2.6
LOWCVE-2006-1640
Cross-site scripting (XSS) vulnerability in news.php in CzarNews 1.14 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : czarnews- EPSS Score: %0.80
- Published: Apr. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3235
Multiple cross-site scripting (XSS) vulnerabilities in index.php in FineShop 3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) promocja, (2) wysw, or (3) id_produc parameters.... Read more
Affected Products : fineshop- EPSS Score: %0.53
- Published: Jun. 27, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2002-0284
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.... Read more
Affected Products : winamp- EPSS Score: %0.45
- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0849
Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.... Read more
Affected Products : windows_media_services- EPSS Score: %9.56
- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3247
Multiple cross-site scripting (XSS) vulnerabilities in show.php in GL-SH Deaf Forum 6.4.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) page, and (3) action parameters. NOTE: the provenance of this info... Read more
Affected Products : deaf_forum- EPSS Score: %0.53
- Published: Jun. 27, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2024-38364
DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institutions worldwide to provide durable access to digital resources. In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream i... Read more
Affected Products : dspace- Published: Jun. 26, 2024
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2006-5800
Cross-site scripting (XSS) vulnerability in default.asp in xenis.creator CMS allows remote attackers to inject arbitrary web script or HTML via the nav parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from t... Read more
Affected Products : xenis.creator_cms- EPSS Score: %0.29
- Published: Nov. 08, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-5847
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.... Read more
Affected Products : constructr-cms- EPSS Score: %1.52
- Published: Jan. 05, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2005-3402
The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection vi... Read more
Affected Products : thunderbird- EPSS Score: %0.29
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1701
Cross-site scripting (XSS) vulnerability in the Pages module in Shadowed Portal allows remote attackers to inject arbitrary web script or HTML via the page parameter to load.php.... Read more
Affected Products : shadowed_portal- EPSS Score: %0.76
- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3044
Cross-site scripting (XSS) vulnerability in LogiSphere 1.6.0 allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected in an error page.... Read more
Affected Products : logisphere- EPSS Score: %0.52
- Published: Jun. 16, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-0179
Cross-site scripting (XSS) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, which is used when composing Forgot Password e-mail m... Read more
Affected Products : liferay_enterprise_portal- EPSS Score: %3.87
- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-1331
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.... Read more
- EPSS Score: %27.11
- Published: Nov. 16, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0892
Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.... Read more
- EPSS Score: %0.66
- Published: Jul. 21, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0091
The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.... Read more
Affected Products : internet_explorer- EPSS Score: %13.45
- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3342
Cross-site scripting (XSS) vulnerability in index.php in Arctic 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search cmd.... Read more
Affected Products : arctic- EPSS Score: %0.62
- Published: Jul. 03, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3848
Cross-site scripting (XSS) vulnerability in CGI wrapper for IP Calculator (IPCalc) 0.40 allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI environment variable), which is used in the actionurl variable.... Read more
Affected Products : ip_calculator- EPSS Score: %0.80
- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3729
DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object, whi... Read more
- EPSS Score: %22.29
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3299
Cross-site scripting (XSS) vulnerability in index.php in Usenet Script 0.5 allows remote attackers to inject arbitrary web script or HTML via the group parameter.... Read more
Affected Products : usenet- EPSS Score: %5.66
- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-1253
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embedded image attachment.... Read more
- EPSS Score: %0.25
- Published: Jun. 04, 2012
- Modified: Apr. 11, 2025