Latest CVE Feed
-
2.6
LOWCVE-2011-5193
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to ... Read more
- Published: Sep. 23, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-3985
Cross-site scripting (XSS) vulnerability in Plume before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : plume_cms- Published: Nov. 09, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-1247
Cross-site scripting (XSS) vulnerability in KENT-WEB WEB MART 1.7 and earlier, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML by leveraging support for Cascading Style Sheets (CSS) expressions.... Read more
Affected Products : web_mart- Published: May. 15, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-3328
The png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when color-correction support is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed PNG image containing a cHRM chunk assoc... Read more
Affected Products : libpng- Published: Jan. 17, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-0208
Multiple cross-site scripting (XSS) vulnerabilities in PHP 4.4.1 and 5.1.1, when display_errors and html_errors are on, allow remote attackers to inject arbitrary web script or HTML via inputs to PHP applications that are not filtered when they are includ... Read more
Affected Products : php- Published: Jan. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-5281
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the co... Read more
Affected Products : enterprise_linux- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2010-0650
WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.... Read more
- Published: Feb. 18, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-2051
The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale. NOTE: this issue is due to an incomplete fix ... Read more
Affected Products : enterprise_linux- Published: Jul. 09, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2017-0096
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtain sensitive information from host O... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_vista- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
2.6
LOWCVE-2015-0820
Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbo... Read more
- Published: Feb. 25, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2010-1157
Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm f... Read more
Affected Products : tomcat- Published: Apr. 23, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-0954
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (M... Read more
- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2007-3474
Multiple unspecified vulnerabilities in the GIF reader in the GD Graphics Library (libgd) before 2.0.35 have unspecified impact and user-assisted remote attack vectors.... Read more
- Published: Jun. 28, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-0995
The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF file, which makes it easier for attackers to decrypt the file via brute force methods.... Read more
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-0180
The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.... Read more
Affected Products : cvs- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2018-0942
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow elevation of privilege, due to how Interne... Read more
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2014-4721
The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attac... Read more
- Published: Jul. 06, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2002-1126
Mozilla 1.1 and earlier, and Mozilla-based browsers such as Netscape and Galeon, set the document referrer too quickly in certain situations when a new page is being loaded, which allows web pages to determine the next page that is being visited, includin... Read more
- Published: Sep. 24, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0649
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.... Read more
- Published: Jul. 13, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2010-4584
Opera before 11.00, when Opera Turbo is used, does not properly present information about problematic X.509 certificates on https web sites, which might make it easier for remote attackers to spoof trusted content via a crafted web site.... Read more
Affected Products : opera_browser- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025