Latest CVE Feed
-
2.6
LOWCVE-2006-3656
Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 200607... Read more
Affected Products : powerpoint- Published: Jul. 18, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-4011
PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the subd parameter.... Read more
Affected Products : esupport- Published: Aug. 07, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2015-7412
The GatewayScript modules on IBM DataPower Gateways with software 7.2.0.x before 7.2.0.1, when the GatewayScript decryption API or a JWE decrypt action is enabled, do not require signed ciphertext data, which makes it easier for remote attackers to obtain... Read more
Affected Products : datapower_gateway- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2012-1413
Cross-site scripting (XSS) vulnerability in zc_install/includes/modules/pages/database_setup/header_php.php in Zen Cart 1.5.0 and earlier, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the db_user... Read more
Affected Products : zen_cart- Published: May. 27, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2012-2567
The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.... Read more
- Published: May. 22, 2012
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2003-1582
Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by i... Read more
Affected Products : internet_information_server- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2010-1856
Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the prod parameter in a products.details action.... Read more
Affected Products : repairshop2- Published: May. 07, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2011-2712
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.18, when setAutomaticMultiWindowSupport is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : wicket- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2008-5847
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.... Read more
Affected Products : constructr-cms- Published: Jan. 05, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2015-7232
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the OSF module 7.x-3.x before 7.x-3.1 for Drupal, when the OSF Ontology module is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vecto... Read more
Affected Products : open_semantic_framework- Published: Sep. 17, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2006-1680
Jupiter CMS 1.1.5, when display_errors is enabled, allows remote attackers to obtain the full server path via a direct request to modules/online.php.... Read more
Affected Products : jupiter_cms- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2006-3399
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki before 1.1.2-20060702 allows remote attackers to inject arbitrary Javascript via the URL, which is reflected back in an error message, a variant of CVE-2004-1632.... Read more
Affected Products : moniwiki- Published: Jul. 06, 2006
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0790
A remote attacker can read information from a Netscape user's cache via JavaScript.... Read more
Affected Products : communicator- Published: Apr. 01, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2007-0685
Internet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service (application crash and device instability) via unspecified vectors, possibly related to a buffer overflow... Read more
- Published: Feb. 03, 2007
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-1999-0869
Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing.... Read more
- Published: Dec. 01, 1998
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0871
Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability.... Read more
Affected Products : internet_explorer- Published: Sep. 04, 1998
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-1009
The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.... Read more
Affected Products : go_express_search- Published: Dec. 12, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-0031
JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.... Read more
- Published: Jul. 08, 1997
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2024-38364
DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institutions worldwide to provide durable access to digital resources. In DSpace 7.0 through 7.6.1, when an HTML, XML or JavaScript Bitstream i... Read more
Affected Products : dspace- Published: Jun. 26, 2024
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2000-0553
Race condition in IPFilter firewall 3.4.3 and earlier, when configured with overlapping "return-rst" and "keep state" rules, allows remote attackers to bypass access restrictions.... Read more
Affected Products : ipfilter- Published: May. 26, 2000
- Modified: Apr. 03, 2025