Latest CVE Feed
-
2.6
LOWCVE-2008-0266
Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks. NOTE: either the old password must be known, or the attacker mu... Read more
Affected Products : eticket- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-0994
Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods.... Read more
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2005-3738
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overwrite variables in the GLOBALS array and conduct various attacks, as demonstrated using the mosConfig_absolute_path parameter to content... Read more
Affected Products : mambo_site_server- Published: Nov. 22, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-0433
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash)... Read more
Affected Products : websphere_application_server- Published: Feb. 10, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-2789
Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-add... Read more
Affected Products : evolution- Published: Jun. 02, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4527
includes/content/gateway.inc.php in CubeCart 3.0.12 and earlier, when magic_quotes_gpc is disabled, uses an insufficiently restrictive regular expression to validate the gateway parameter, which allows remote attackers to conduct PHP remote file inclusion... Read more
Affected Products : cubecart- Published: Sep. 01, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4650
Cisco IOS 12.0, 12.1, and 12.2, when GRE IP tunneling is used and the RFC2784 compliance fixes are missing, does not verify the offset field of a GRE packet during decapsulation, which leads to an integer overflow that references data from incorrect memor... Read more
Affected Products : ios- Published: Sep. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4673
Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.... Read more
- Published: Sep. 11, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2002-0422
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 20... Read more
Affected Products : internet_information_services- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-4308
The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.... Read more
Affected Products : tomcat- Published: Feb. 26, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-0274
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.... Read more
Affected Products : drupal- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-3320
Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the command parameter.... Read more
Affected Products : sitebar- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3061
Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web script or HTML via the (1) sort parameter in index2.php, (2) item_id parameter in report.php, (3) search_term parameter (aka the "search bo... Read more
Affected Products : five_star_review_script- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4570
Mozilla Thunderbird before 1.5.0.7 and SeaMonkey before 1.0.5, with "Load Images" enabled, allows remote user-assisted attackers to bypass settings that disable JavaScript via a remote XBL file in a message that is loaded when the user views, forwards, or... Read more
- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-4022
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache ... Read more
Affected Products : bind- Published: Nov. 25, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-2728
Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the pic parameter.... Read more
Affected Products : photoalbum_bandw- Published: Jun. 01, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2729
Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the gal parameter. NOTE: the provenance of this information is unknown; the details are obtained sol... Read more
Affected Products : photoalbum_bandw- Published: Jun. 01, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-0475
Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLH... Read more
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-3039
Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Home Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this scri... Read more
Affected Products : realty_home_rent- Published: Jun. 15, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4369
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via an absolute pathname in the phpbb_root_path parameter.... Read more
Affected Products : integramod_portal- Published: Aug. 26, 2006
- Modified: Apr. 03, 2025