Latest CVE Feed
-
2.6
LOWCVE-2013-0181
Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which ... Read more
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-0244
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving u... Read more
Affected Products : drupal- Published: Jan. 19, 2014
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-2712
Multiple cross-site scripting (XSS) vulnerabilities in the Search API module 7.x-1.x before 7.x-1.1 for Drupal, when supporting manual entry of field identifiers, allow remote attackers to inject arbitrary web script or HTML via vectors related to thrown ... Read more
- Published: Jun. 27, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-2731
The Ubercart AJAX Cart 6.x-2.x before 6.x-2.1 for Drupal stores the PHP session id in the JavaScript settings array in page loads, which might allow remote attackers to obtain sensitive information by sniffing or reading the cache of the HTML of a webpage... Read more
- Published: Jun. 27, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-4600
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote attackers to inject arbitrary web script or HTML via an... Read more
- Published: Aug. 31, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-5559
Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with permissions to submit or edit nodes to inject arbitrary web scrip... Read more
Affected Products : ctools- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-2710
Cross-site scripting (XSS) vulnerability in the Zen module 6.x-1.x before 6.x-1.1 for Drupal, when "Append the content title to the end of the breadcrumb" is enabled, allows remote attackers to inject arbitrary web script or HTML via the content title in ... Read more
- Published: Jun. 27, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-5460
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect confidentiality via unknown vectors.... Read more
Affected Products : bea_product_suite- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2012-6502
Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathname in the SRC attribute of a SCRIPT element, as demonstrated by reading a n... Read more
Affected Products : internet_explorer- Published: Jan. 22, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-2632
SEIL routers with firmware SEIL/x86 1.00 through 2.35, SEIL/X1 2.30 through 3.75, SEIL/X2 2.30 through 3.75, and SEIL/B1 2.30 through 3.75, when the http-proxy and application-gateway features are enabled, do not properly handle the CONNECT command, which... Read more
- Published: Jun. 15, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-2634
Cross-site scripting (XSS) vulnerability in FeedDemon before 4.0, when the feed preview option is enabled, allows remote attackers to inject arbitrary web script or HTML via a feed.... Read more
Affected Products : feeddemon- Published: Jun. 15, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-4037
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file.... Read more
Affected Products : transmission- Published: Aug. 15, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2014-0595
/opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the gran... Read more
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-0591
The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV before 9.6-ESV-R10-P2, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exi... Read more
Affected Products : bind- Published: Jan. 14, 2014
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2024-28864
SecureProps is a PHP library designed to simplify the encryption and decryption of property data in objects. A vulnerability in SecureProps version 1.2.0 and 1.2.1 involves a regex failing to detect tags during decryption of encrypted data. This occurs wh... Read more
Affected Products :- Published: Mar. 18, 2024
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2005-1049
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could... Read more
Affected Products : postnuke- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0232
Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen... Read more
Affected Products : firefox- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2009-0071
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) q... Read more
Affected Products : firefox- Published: Jan. 08, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2004-0837
MySQL 4.x before 4.0.21, and 3.x before 3.23.49, allows attackers to cause a denial of service (crash or hang) via multiple threads that simultaneously alter MERGE table UNIONs.... Read more
- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2011-1499
acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy serv... Read more
- Published: Apr. 29, 2011
- Modified: Apr. 11, 2025