Latest CVE Feed
-
2.6
LOWCVE-2012-2567
The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.... Read more
- Published: May. 22, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-1413
Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_user... Read more
Affected Products : zen_cart- Published: May. 27, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-5847
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.... Read more
Affected Products : constructr-cms- Published: Jan. 05, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2014-2431
Unspecified vulnerability in Oracle MySQL Server 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect availability via unknown vectors related to Options.... Read more
- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-6527
Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-6476.... Read more
Affected Products : jre- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-3966
Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 1.19.16, 1.21.x before 1.21.10, and 1.22.x before 1.22.7, when wgRawHtml is enabled, allows remote attackers to inject arbitrary web script or HTML via an invalid userna... Read more
Affected Products : mediawiki- Published: Jun. 06, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2013-2207
pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.... Read more
- Published: Oct. 09, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-1729
The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element.... Read more
- Published: Sep. 18, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2014-1690
The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet data is transmitted during use of the... Read more
- Published: Feb. 28, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2015-5667
Cross-site scripting (XSS) vulnerability in the HTML-Scrubber module before 0.15 for Perl, when the comment feature is enabled, allows remote attackers to inject arbitrary web script or HTML via a crafted comment.... Read more
Affected Products : html-scrubber- Published: Oct. 31, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-9269
Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.... Read more
- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-2420
Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect integrity via unknown vectors related to Deployment.... Read more
- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2013-5854
Unspecified vulnerability in Oracle Java SE 7u40 and earlier and JavaFX 2.2.40 and earlier allows remote attackers to affect confidentiality via unknown vectors.... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2007-3820
konqueror/konq_combo.cc in Konqueror 3.5.7 allows remote attackers to spoof the data: URI scheme in the address bar via a long URI with trailing whitespace, which prevents the beginning of the URI from being displayed.... Read more
Affected Products : konqueror- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2007-3807
Multiple cross-site scripting (XSS) vulnerabilities in SiteScape Forum before 7.3 allow remote attackers to inject arbitrary web script or HTML via the user name field in the login procedure, and other unspecified vectors.... Read more
Affected Products : sitescape_forum- Published: Jul. 17, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2011-3649
Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, ... Read more
- Published: Nov. 09, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-2960
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries... Read more
Affected Products : phpmyadmin- Published: Jul. 02, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2008-3457
Cross-site scripting (XSS) vulnerability in setup.php in phpMyAdmin before 2.11.8 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted setup arguments. NOTE: this issue can only be exploited in limited scenarios in whi... Read more
Affected Products : phpmyadmin- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2011-3266
The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and 1.4.0 through 1.4.8, when the IKEv1 protocol dissector is used, allows user-assisted remote attackers to cause a denial of service (infinite loop) via vectors involving a malformed IKE ... Read more
Affected Products : wireshark- Published: Aug. 24, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-5161
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IB... Read more
- Published: Nov. 19, 2008
- Modified: Apr. 09, 2025