Latest CVE Feed
-
2.6
LOWCVE-2004-0124
The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."... Read more
- Published: Jun. 01, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-0286
Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07.... Read more
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-0895
Race condition in recursive directory deletion with the (1) -r or (2) -R option in rm in Solaris 8 through 10 before 20070208 allows local users to delete files and directories as the user running rm by moving a low-level directory to a higher level as it... Read more
- Published: Feb. 13, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-1903
Cross-site scripting (XSS) vulnerability in search.php in SonicBB 1.0 allows remote attackers to inject arbitrary web script or HTML via the part parameter.... Read more
Affected Products : sonicbb- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-2727
The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which mi... Read more
Affected Products : php- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-5791
Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the filename for downloading, which is not quoted in an error message by the send_file_direct fu... Read more
Affected Products : elog_web_logbook- Published: Nov. 07, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-4374
IrfanView 3.98 (with plugins) allows user-assisted attackers to cause a denial of service (application crash) via a crafted ANI image file, possibly due to a buffer overflow.... Read more
Affected Products : irfanview- Published: Aug. 26, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0492
Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.... Read more
Affected Products : acrobat_reader- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0870
Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste.... Read more
Affected Products : internet_explorer- Published: Oct. 01, 1998
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-1263
Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as s... Read more
Affected Products : metamail- Published: Aug. 15, 2003
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0501
Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command and quickly exiting the server.... Read more
Affected Products : mdaemon- Published: Jun. 16, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2002-0292
Cross-site scripting vulnerability in Slash before 2.2.5, as used in Slashcode and elsewhere, allows remote attackers to steal cookies and authentication information from other users via Javascript in a URL, possibly in the formkey field.... Read more
Affected Products : slashcode- Published: May. 31, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0273
pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.... Read more
Affected Products : pgp4pine- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2008-3574
Multiple cross-site scripting (XSS) vulnerabilities in Pluck 4.5.2, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) lang_footer parameter to (a) data/inc/footer.php; the (2) pluck_version, (3) la... Read more
- Published: Aug. 10, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2000-0439
Internet Explorer 4.0 and 5.0 allows a malicious web site to obtain client cookies from another domain by including that domain name and escaped characters in a URL, aka the "Unauthorized Cookie Access" vulnerability.... Read more
Affected Products : internet_explorer- Published: May. 11, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0950
unalz 0.53 allows user-assisted attackers to overwrite arbitrary files via an ALZ archive with ".." (dot dot) sequences in a filename.... Read more
Affected Products : unalz- Published: Mar. 13, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0927
Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slidesh... Read more
- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2002-1813
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link.... Read more
Affected Products : instant_messenger- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0382
ColdFusion ClusterCATS appends stale query string arguments to a URL during HTML redirection, which may provide sensitive information to the redirected site.... Read more
Affected Products : clustercats- Published: May. 08, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2001-0092
A function in Internet Explorer 5.0 through 5.5 does not properly verify the domain of a frame within a browser window, which allows a remote attacker to read client files, aka a new variant of the "Frame Domain Verification" vulnerability.... Read more
Affected Products : internet_explorer- Published: Feb. 16, 2001
- Modified: Apr. 03, 2025