Latest CVE Feed
-
2.6
LOWCVE-2015-8035
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.... Read more
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-7094
CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle attackers to bypass the HSTS protection mechanism via a crafted URL.... Read more
- Published: Dec. 11, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-3886
Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.... Read more
Affected Products : webmin- Published: Jul. 20, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-6921
Cross-site scripting (XSS) vulnerability in the Zendesk Feedback Tab module 7.x-1.x before 7.x-1.1 for Drupal allows remote administrators with the "Configure Zendesk Feedback Tab" permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : zendesk_feedback_tab- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-8233
Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.6 for Drupal allows remote administrators with the "Administer themes" permission to inject arbitrary web script or HTML via unspecified vectors rel... Read more
Affected Products : mayo- Published: Nov. 17, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2007-1358
Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RF... Read more
Affected Products : tomcat- Published: May. 10, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2005-0664
Buffer overflow in the EXIF library (libexif) 0.6.9 does not properly validate the structure of the EXIF tags, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a JPEG image with a craft... Read more
Affected Products : libexif- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-3450
pdo_sql_parser.re in the PDO extension in PHP before 5.3.14 and 5.4.x before 5.4.4 does not properly determine the end of the query string during parsing of prepared statements, which allows remote attackers to cause a denial of service (out-of-bounds rea... Read more
Affected Products : php- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-2431
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.... Read more
Affected Products : cups- Published: Jun. 22, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2015-2627
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 allows remote attackers to affect confidentiality via unknown vectors related to installation.... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2005-0584
Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2126
The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite fi... Read more
- Published: Oct. 21, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-0504
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Error Messages.... Read more
Affected Products : e-business_suite- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2005-2274
Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofi... Read more
Affected Products : internet_explorer- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2000-0649
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.... Read more
- Published: Jul. 13, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0144
Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0903
Buffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file with crafted Huffman Table (marker DHT) data.... Read more
Affected Products : quicktime_pictureviewer- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0141
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-5281
The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the co... Read more
Affected Products : enterprise_linux- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2025-55285
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the input values in the fetch:template action in the Scaffolder meant that some of the secrets were not properly... Read more
Affected Products : backstage- Published: Aug. 15, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Information Disclosure