Latest CVE Feed
-
2.6
LOWCVE-2015-4346
Cross-site scripting (XSS) vulnerability in the SMS Framework module 6.x-1.x before 6.x-1.1 for Drupal, when the "Send to phone" submodule is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to messag... Read more
Affected Products : sms_framework- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-2047
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty value.... Read more
- Published: Feb. 23, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-4926
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.1, and 12.2 allows remote attackers to affect integrity via vectors related to UIX.... Read more
Affected Products : e-business_suite- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-4456
ownCloud Desktop Client before 1.8.2 does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which allows man-in-the-middle attackers to bypass the user's certificate distrust decision and obtain sensitive information by levera... Read more
Affected Products : owncloud_desktop_client- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2016-3291
Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."... Read more
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-5514
Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x before 7.x-2.8 for Drupal, when the migrate_ui submodule is enabled, allows user-assisted remote attackers to inject arbitrary web script or HTML via a destination field label.... Read more
Affected Products : migrate- Published: Aug. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2005-3110
Race condition in ebtables netfilter module (ebtables.c) in Linux 2.6, when running on an SMP system that is operating under a heavy load, might allow remote attackers to cause a denial of service (crash) via a series of packets that cause a value to be m... Read more
- Published: Sep. 30, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0898
Crypt::CBC Perl module 2.16 and earlier, when running in RandomIV mode, uses an initialization vector (IV) of 8 bytes, which results in weaker encryption when used with a cipher that requires a larger block size than 8 bytes, such as Rijndael.... Read more
Affected Products : crypt_cbc- Published: Feb. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-4456
Cross-site scripting (XSS) vulnerability in the command-line client in MySQL 5.0.26 through 5.0.45, and other versions including versions later than 5.0.45, when the --html option is enabled, allows attackers to inject arbitrary web script or HTML by plac... Read more
- Published: Oct. 06, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-0808
Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating user interaction with the AutoComplete feature, which allows remote attackers to obtain sensitive form information via a crafted web site, aka "AutoComplet... Read more
- Published: Oct. 13, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2005-2534
Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.... Read more
Affected Products : openvpn- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3264
Cross-site scripting (XSS) vulnerability in mclient.cgi in Namo DeepSearch 4.5 allows remote attackers to inject arbitrary web script or HTML via the p parameter.... Read more
Affected Products : deepsearch- Published: Jun. 27, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3104
mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments.... Read more
Affected Products : movable_type- Published: Sep. 28, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-0717
IBM WebSphere Application Server 7.0 before 7.0.0.23, when a certain SSLv2 configuration with client authentication is used, allows remote attackers to bypass X.509 client-certificate authentication via unspecified vectors.... Read more
Affected Products : websphere_application_server- Published: Jun. 20, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-6146
Buffer overflow in the HPDF_Page_Circle function in hpdf_page_operator.c in Takeshi Kanno Haru Free PDF Library (libharu2, aka libharu) 2.0.7 and earlier allows context-dependent attackers to cause a denial of service (application crash) via certain argum... Read more
Affected Products : haru_free_pdf_library- Published: Nov. 28, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2001-0184
eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.... Read more
Affected Products : iris- Published: Mar. 26, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2013-2318
The Content Provider in the MovatwiTouch application before 1.793 and MovatwiTouch Paid application before 1.793 for Android does not properly restrict access to authorization information, which allows attackers to hijack Twitter accounts via a crafted ap... Read more
- Published: Jun. 06, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-5914
Multiple cross-site scripting (XSS) vulnerabilities in the sed_import function in system/functions.php in Neocrome Seditio build 160 and 161 allow remote attackers to inject arbitrary web script or HTML via the (1) newmsg or (2) rtext parameter. NOTE: so... Read more
Affected Products : seditio- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2015-5281
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the co... Read more
Affected Products : enterprise_linux- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2024-45719
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users a... Read more
Affected Products : answer- Published: Nov. 22, 2024
- Modified: Jul. 01, 2025