Latest CVE Feed
-
2.6
LOWCVE-2006-5069
Cross-site scripting (XSS) vulnerability in class.tx_indexedsearch.php in the Indexed Search 2.9.0 extension for Typo3 before 4.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : typo3- Published: Sep. 28, 2006
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1665
Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0.1 stable allow remote attackers to inject arbitrary web script or HTML via the (1) adminJump and (2) forum_middle parameters in (a) forum.php, and the (3) form parameter in (b) members... Read more
Affected Products : arab_portal- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2414
Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, ... Read more
Affected Products : xpcom- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2010-3560
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.... Read more
- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-2332
Mozilla Firefox 1.5.0.3 allows remote attackers to cause a denial of service via a web page with a large number of IMG elements in which the SRC attribute is a mailto URI. NOTE: another researcher found that the web page caused a temporary browser slowdo... Read more
Affected Products : firefox- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0770
Cross-site scripting (XSS) vulnerability in calendar.php in MyBulletinBoard (MyBB) 1.0.4 allows remote attackers to inject arbitrary web script or HTML via a URL that is not sanitized before being returned as a link in "advanced details". NOTE: the prove... Read more
Affected Products : mybulletinboard- Published: Feb. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2766
Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a lon... Read more
- Published: Jun. 02, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-0641
Orbicule Undercover uses a third-party web server to determine the IP address through which the computer is accessing the Internet, but does not document this third-party disclosure, which leads to a potential privacy leak that might allow transmission of... Read more
Affected Products : undercover- Published: Feb. 10, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3253
Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the i... Read more
Affected Products : vbulletin- Published: Jun. 28, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-5420
The 3Com 3CRWER100-75 router with 1.2.10ww software, when remote management is disabled but a web server has been configured, serves a web page to external clients, which might allow remote attackers to obtain information about the router's existence and ... Read more
Affected Products : 3crwe554g72t- Published: Oct. 12, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2002-1233
A regression error in the Debian distributions of the apache-ssl package (before 1.3.9 on Debian 2.2, and before 1.3.26 on Debian 3.0), for Apache 1.3.27 and earlier, allows local users to read or modify the Apache password file via a symlink attack on te... Read more
Affected Products : http_server- Published: Nov. 04, 2002
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-5293
Multiple cross-site scripting (XSS) vulnerabilities in IDMOS 1.0-beta (aka Phoenix) allow remote attackers to inject arbitrary web script or HTML via the (1) err_msg parameter to error.php and the (2) content parameter to templates/simple/ia.php.... Read more
Affected Products : idmos- Published: Oct. 09, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2010-2751
The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors in... Read more
- Published: Jul. 30, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2007-5564
Multiple cross-site scripting (XSS) vulnerabilities in NSSboard (formerly Simple PHP Forum) 6.1 allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags when BBcode is disabled; or the (2) user, (3) email, or (4) Real Name fields in... Read more
Affected Products : simple_php_forum- Published: Oct. 18, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2003-0282
Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.... Read more
- Published: Jun. 16, 2003
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-5414
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit... Read more
Affected Products : firefox- Published: Oct. 12, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-5375
Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that ... Read more
Affected Products : java_virtual_machine- Published: Oct. 11, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-0994
Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods.... Read more
- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-1877
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently revea... Read more
- Published: Mar. 30, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-5578
Microsoft Internet Explorer 6 and earlier allows remote attackers to read Temporary Internet Files (TIF) and obtain sensitive information via unspecified vectors involving certain drag and drop operations, aka "TIF Folder Information Disclosure Vulnerabil... Read more
Affected Products : ie- Published: Dec. 12, 2006
- Modified: Apr. 09, 2025