Latest CVE Feed
-
4.3
MEDIUMCVE-2011-3444
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.... Read more
- Published: Feb. 02, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5223
Cross-site request forgery (CSRF) vulnerability in logout.php in Cacti before 0.8.7i allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more
Affected Products : cacti- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1117
Cross-site scripting (XSS) vulnerability in Joomla! 2.5.0 and 2.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0451
CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Poli... Read more
- Published: Mar. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5221
Cross-site scripting (XSS) vulnerability in the getLog function in svnlook.php in WebSVN before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to (1) comp.php, (2) diff.php, or (3) revision.php.... Read more
Affected Products : websvn- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-1278
content/browser/web_contents/web_contents_impl.cc in Google Chrome before 44.0.2403.89 does not ensure that a PDF document's modal dialog is closed upon navigation to an interstitial page, which allows remote attackers to spoof URLs via a crafted document... Read more
- Published: Jul. 23, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-1162
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due to missing or incorrect nonce validation on the register_reference() function. This makes it possible fo... Read more
Affected Products : orbit_fox- Published: Feb. 02, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-1154
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictio... Read more
- Published: Oct. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5209
Cross-site scripting (XSS) vulnerability in search/ in GraphicsClone Script, possibly 1.11, allows remote attackers to inject arbitrary web script or HTML via the term parameter.... Read more
Affected Products : graphicsclone_script- Published: Oct. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0455
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascrip... Read more
- Published: Mar. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5206
Cross-site scripting (XSS) vulnerability in notes.php in Rapidleech before 2.3 rev42 SVN r399 allows remote attackers to inject arbitrary web script or HTML via the notes parameter.... Read more
Affected Products : rapidleech- Published: Oct. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1161
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results... Read more
- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-5214
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) modules/admin/admin_module_index.php, or (3) modules/calendar/cust... Read more
Affected Products : browsercrm- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0428
Cross-site scripting (XSS) vulnerability in NetIQ eDirectory 8.8.6.x before 8.8.6.7 and 8.8.7.x before 8.8.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1465
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause a denial of service (application crash) via a long URL in an HTTP request. NOTE: some of these details are obtained from third party ... Read more
Affected Products : netdecision- Published: Mar. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0496
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows remote authenticated users to affect confidentiality and integrity via unknown vectors.... Read more
Affected Products : mysql- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5305
Multiple cross-site scripting (XSS) vulnerabilities in CosmoShop ePRO 10.05.00 allow remote attackers to inject arbitrary web script or HTML via (1) the rcopy parameter to cgi-bin/admin/rubrikadmin.cgi, (2) the typ parameter to cgi-bin/admin/artikeladmin.... Read more
Affected Products : cosmoshop- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-15959
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.... Read more
- Published: Sep. 21, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-3404
Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site,... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_server_2003 windows_vista windows_xp- Published: Dec. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-38417
Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20 may allow an unauthenticated user to potentially enable denial of service via adjacent access.... Read more
Affected Products :- Published: May. 16, 2024
- Modified: Nov. 21, 2024