Latest CVE Feed
-
2.6
LOWCVE-2006-1969
Cross-site scripting (XSS) vulnerability in search/search.cgi in an unspecified KCScripts script, probably Search Engine or Site Search, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web s... Read more
Affected Products : portal_pack- Published: Apr. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-5256
Cross-site scripting (XSS) vulnerability in the tooltips in LimeSurvey before 1.91+ Build 11379-20111116, when viewing survey results, allows remote attackers to inject arbitrary web script or HTML via unknown parameters.... Read more
Affected Products : limesurvey- Published: Feb. 12, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-0099
Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to sshd.... Read more
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2014-1504
The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted docum... Read more
Affected Products : firefox opensuse solaris linux_enterprise_server seamonkey linux_enterprise_desktop linux_enterprise_sdk- Published: Mar. 19, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2012-6502
Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a n... Read more
Affected Products : internet_explorer- Published: Jan. 22, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-5193
Cross-site scripting (XSS) vulnerability in vendors/samswhois/samswhois.inc.php in the Whois Search plugin 1.4.2.3 for WordPress, when the WHOIS widget is enabled, allows remote attackers to inject arbitrary web script or HTML via the domain parameter to ... Read more
- Published: Sep. 23, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-3122
Unspecified vulnerability in Oracle Sun Solaris 8 and 9 allows local users to affect confidentiality and integrity via unknown vectors related to sort.... Read more
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-2322
Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831. NOTE: th... Read more
Affected Products : fastjar- Published: Jun. 18, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2009-2268
Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7 2005Q4, and 7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : java_system_access_manager- Published: Jul. 01, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1908
Cross-site scripting vulnerability in addevent.php in myEvent 1.x allows remote attackers to inject arbitrary web script or HTML via the event_desc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third... Read more
Affected Products : myevent- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2093
Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep parameter. NOTE: a design goal of the NASL language is to facilitate sharin... Read more
Affected Products : nessus- Published: Apr. 29, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1494
Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.... Read more
Affected Products : php- Published: Apr. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0053
Imager (libimager-perl) before 0.50 allows user-assisted attackers to cause a denial of service (segmentation fault) by writing a 2- or 4-channel JPEG image (or a 2-channel TGA image) to a scalar, which triggers a NULL pointer dereference.... Read more
Affected Products : imager- Published: Apr. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2016
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d) template_engi... Read more
- Published: Apr. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1045
The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive informati... Read more
Affected Products : thunderbird- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2010-0132
Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to "search_re input,... Read more
Affected Products : viewvc- Published: Mar. 31, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-2071
java/org/apache/catalina/core/AsyncContextImpl.java in Apache Tomcat 7.x before 7.0.40 does not properly handle the throwing of a RuntimeException in an AsyncListener in an application, which allows context-dependent attackers to obtain sensitive request ... Read more
Affected Products : tomcat- Published: Jun. 01, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-2988
Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CV... Read more
Affected Products : cognos_business_intelligence- Published: Aug. 27, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-5099
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, b... Read more
Affected Products : anchor_cms- Published: Aug. 09, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-5183
Mail in Apple Mac OS X before 10.9, when Kerberos authentication is enabled and TLS is disabled, sends invalid cleartext data, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more
- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025