Latest CVE Feed
-
2.6
LOWCVE-2006-4210
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these deta... Read more
Affected Products : phpay- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0849
Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.... Read more
Affected Products : windows_media_services- Published: Nov. 14, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0892
Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL.... Read more
- Published: Jul. 21, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2004-1331
The execCommand method in Microsoft Internet Explorer 6.0 SP2 allows remote attackers to bypass the "File Download - Security Warning" dialog and save arbitrary files with arbitrary extensions via the SaveAs command.... Read more
- Published: Nov. 16, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0091
The ActiveX control for invoking a scriptlet in Internet Explorer 5.0 through 5.5 renders arbitrary file types instead of HTML, which allows an attacker to read arbitrary files, aka a variant of the "Scriptlet Rendering" vulnerability.... Read more
Affected Products : internet_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2013-5854
Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality via unknown vectors.... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2007-4679
CFFTP in CFNetwork for Apple Mac OS X 10.4 through 10.4.10 allows remote FTP servers to force clients to connect to other hosts via crafted responses to FTP PASV commands.... Read more
Affected Products : mac_os_x- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-2751
The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors in... Read more
- Published: Jul. 30, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-1729
The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element.... Read more
- Published: Sep. 18, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-2957
Cross-site scripting (XSS) vulnerability in Serendipity before 1.5.4, when "Remember me" logins are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : serendipity- Published: Sep. 10, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2014-0046
Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allows remote attackers to inject arbitrary web script or HTML via the title att... Read more
Affected Products : ember.js- Published: Feb. 27, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-7412
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain... Read more
Affected Products : datapower_gateway- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-7232
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology module is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vecto... Read more
Affected Products : open_semantic_framework- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2007-5710
Cross-site scripting (XSS) vulnerability in wp-admin/edit-post-rows.php in WordPress 2.3 allows remote attackers to inject arbitrary web script or HTML via the posts_columns array parameter.... Read more
Affected Products : wordpress- Published: Oct. 30, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-0274
Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.... Read more
Affected Products : drupal- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2025-48938
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing arbitrary commands... Read more
Affected Products :- Published: May. 30, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Path Traversal
-
2.6
LOWCVE-2006-0753
Memory leak in Microsoft Internet Explorer 6 for Windows XP Service Pack 2 allows remote attackers to cause a denial of service (memory consumption) via JavaScript that uses setInterval to repeatedly call a function to set the value of window.status.... Read more
Affected Products : ie- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-2140
Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.... Read more
Affected Products : appliance_platform_agent- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-4164
cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.... Read more
Affected Products : memht_portal- Published: Sep. 22, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-4685
The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.... Read more
- Published: Oct. 10, 2006
- Modified: Apr. 09, 2025