Latest CVE Feed
-
2.6
LOWCVE-2006-3729
DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object, whi... Read more
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3848
Cross-site scripting (XSS) vulnerability in CGI wrapper for IP Calculator (IPCalc) 0.40 allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI environment variable), which is used in the actionurl variable.... Read more
Affected Products : ip_calculator- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-1001
Cisco Cache Engine allows a remote attacker to gain access via a null username and password.... Read more
Affected Products : cache_engine- Published: Dec. 16, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4210
nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these deta... Read more
Affected Products : phpay- Published: Aug. 17, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-4494
Cross-site scripting (XSS) vulnerability in SPIP 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) spip_login.php3 and (2) spip_pass.php3.... Read more
Affected Products : spip- Published: Dec. 22, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-1226
Netscape Communicator 4.7 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long certificate key.... Read more
Affected Products : communicator- Published: Oct. 28, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2021-29473
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading,... Read more
- Published: Apr. 26, 2021
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2024-45719
Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some extent not secure enough. It can cause the generated token to be predictable. Users a... Read more
Affected Products : answer- Published: Nov. 22, 2024
- Modified: Jul. 01, 2025
-
2.6
LOWCVE-2018-0942
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow elevation of privilege, due to how Interne... Read more
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2014-1380
The Security - Keychain component in Apple OS X before 10.9.4 does not properly implement keystroke observers, which allows physically proximate attackers to bypass the screen-lock protection mechanism, and enter characters into an arbitrary window under ... Read more
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2012-3216
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, 5.0 Update 36 and earlier, and 1.4.2_38 and earlier allows remote attackers to affect confidentiality via unknown ... Read more
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-1945
The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easi... Read more
Affected Products : openssl- Published: May. 31, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2014-3737
Cross-site scripting (XSS) vulnerability in templates/defaultheader.php in Lamp Design Storesprite before 7 - 19-06-14, when using the currency selection dropdown, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to brand.p... Read more
Affected Products : storesprite- Published: Jul. 02, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2007-5274
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the ... Read more
- Published: Oct. 08, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2014-2478
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote attackers to affect confidentiality via unknown vectors.... Read more
Affected Products : database_server- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2012-2947
chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1, when a certain mohinterpret setting is enabled, allows remote attackers to cause a denial o... Read more
- Published: Jun. 02, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2015-8035
The xz_decomp function in xzlib.c in libxml2 2.9.1 does not properly detect compression errors, which allows context-dependent attackers to cause a denial of service (process hang) via crafted XML data.... Read more
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2012-0954
APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attackers to install altered packages via a man-in-the-middle (M... Read more
- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2013-2051
The Tomcat 6 DIGEST authentication functionality as used in Red Hat Enterprise Linux 6 allows remote attackers to bypass intended access restrictions by performing a replay attack after a nonce becomes stale. NOTE: this issue is due to an incomplete fix ... Read more
Affected Products : enterprise_linux- Published: Jul. 09, 2013
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2015-0820
Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbo... Read more
- Published: Feb. 25, 2015
- Modified: Apr. 12, 2025