Latest CVE Feed
-
2.6
LOWCVE-2006-2332
Mozilla Firefox 1.5.0.3 allows remote attackers to cause a denial of service via a web page with a large number of IMG elements in which the SRC attribute is a mailto URI. NOTE: another researcher found that the web page caused a temporary browser slowdo... Read more
Affected Products : firefox- Published: May. 12, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2013-0962
Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 6.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted content that is not properly handled during a copy-and-paste operation.... Read more
Affected Products : iphone_os- Published: Jan. 29, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-4661
AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) does not properly validate the origin of the configuration web page (options2.html), which allows user-assisted remote attackers to provide a web page that contains disguised checkboxes that trick t... Read more
Affected Products : icq_toolbar- Published: Sep. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-0354
Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors invol... Read more
Affected Products : firefox- Published: Feb. 04, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2015-1787
The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allows remote attackers to cause a denial of service (daemon crash) via a ClientKeyE... Read more
Affected Products : openssl- Published: Mar. 19, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2006-2312
Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains certain command-line switches.... Read more
- Published: May. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2265
Cross-site scripting vulnerability in admin/main.asp in Ocean12 Calendar Manager Pro 1.00 allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: the provenance of this information is unknown; the details are obtained... Read more
Affected Products : calendar_manager_pro- Published: May. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2012-1164
slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attributes to be returned.... Read more
Affected Products : openldap- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-0158
Unspecified vulnerability in Jenkins before 1.498, Jenkins LTS before 1.480.2, and Jenkins Enterprise 1.447.x before 1.447.6.1 and 1.466.x before 1.466.12.1, when a slave is attached and anonymous read access is enabled, allows remote attackers to obtain ... Read more
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2006-4919
Directory traversal vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the dir parameter.... Read more
Affected Products : siteatschool- Published: Sep. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-2258
Cross-site scripting (XSS) vulnerability in Logon.asp in MaxxSchedule 1.0 allows remote attackers to inject arbitrary web script or HTML via the Error parameter.... Read more
Affected Products : maxxschedule- Published: May. 09, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-3455
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers... Read more
- Published: May. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2012-0287
Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the query string in a POST operation that is not properly ... Read more
- Published: Jan. 06, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-4308
The doRead method in Apache Tomcat 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 does not return a -1 to indicate when a certain error condition has occurred, which can cause Tomcat to send POST content from one request to a different request.... Read more
Affected Products : tomcat- Published: Feb. 26, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2009-1536
ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a ser... Read more
- Published: Aug. 12, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2006-1843
Cross-site scripting (XSS) vulnerability in global.php in ShoutBOOK 1.1 allows remote attackers to inject arbitrary web script or HTML via the (1) LOCATION and (2) URL parameters. NOTE: the provenance of this information is unknown; the details are obtai... Read more
Affected Products : shoutbook- Published: Apr. 19, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1808
Cross-site scripting (XSS) vulnerability in index.php in Lifetype 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the show parameter in a Template operation.... Read more
Affected Products : lifetype- Published: Apr. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1943
Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addlink_lwp.cgi and the (2) id, (3) forgotid, and (4) forgot... Read more
Affected Products : intellilink_pro- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1224
Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.... Read more
Affected Products : guppy- Published: Mar. 14, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-1946
Multiple cross-site scripting (XSS) vulnerabilities in Visale 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the keyval parameter in pbpgst.cgi, (2) the catsubno parameter in pblscg.cgi, and (3) the listno parameter ... Read more
Affected Products : visale- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025