Latest CVE Feed
-
4.3
MEDIUMCVE-2015-7424
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access. IBM X-Force I... Read more
Affected Products : infosphere_master_data_management- Published: Mar. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1686
The Microsoft (1) VBScript 5.6 through 5.8 and (2) JScript 5.6 through 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScr... Read more
- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6459
Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.... Read more
Affected Products : will_paginate- Published: Dec. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2889
Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors involving frames, aka "Universal XSS (UXSS)."... Read more
- Published: Sep. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-1441
The 4thPass browser (BlackBerry Browser) on the RIM BlackBerry 8100 (Pearl) before 4.2.1 allows remote attackers to cause a denial of service (temporary functionality loss) via a long href attribute in a link in a WML page.... Read more
- Published: Mar. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-1917
Cross-site scripting (XSS) vulnerability in the Active Content Filtering component in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote a... Read more
Affected Products : websphere_portal- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2865
Google Chrome before 21.0.1180.89 does not properly perform line breaking, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.... Read more
- Published: Aug. 31, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-1003027
A server-side request forgery vulnerability exists in Jenkins OctopusDeploy Plugin 1.8.1 and earlier in OctopusDeployPlugin.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified URL and obtain the HTTP re... Read more
Affected Products : octopusdeploy- Published: Feb. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-1003026
A server-side request forgery vulnerability exists in Jenkins Mattermost Notification Plugin 2.6.2 and earlier in MattermostNotifier.java that allows attackers with Overall/Read permission to have Jenkins connect to an attacker-specified Mattermost server... Read more
- Published: Feb. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2053
The log viewer in McAfee Agent (MA) before 4.8.0 Patch 3 and 5.0.0, when the "Accept connections only from the ePO server" option is disabled, allows remote attackers to conduct clickjacking attacks via a crafted web page, aka an "http-generic-click-jacki... Read more
Affected Products : mcafee_agent- Published: Feb. 23, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5131
Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : iphone_os- Published: Sep. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6626
The WebContentsImpl::AttachInterstitialPage function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 31.0.1650.48 does not cancel JavaScript dialogs upon generating an interstitial warning, which allows remote attackers to spo... Read more
Affected Products : chrome- Published: Nov. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-2270
lib/moodlelib.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4, when the theme uses the blocks-regions feature, establishes the course state at an incorrect point in the login-validation process, which allows rem... Read more
Affected Products : moodle- Published: Jun. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-2576
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules a... Read more
Affected Products : gitlab- Published: Jul. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2654
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows ... Read more
- Published: Jun. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2552
Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML v... Read more
- Published: Oct. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-1003020
A server-side request forgery vulnerability exists in Jenkins Kanboard Plugin 1.5.10 and earlier in KanboardGlobalConfiguration.java that allows attackers with Overall/Read permission to submit a GET request to an attacker-specified URL.... Read more
Affected Products : kanboard- Published: Feb. 06, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6623
The SVG implementation in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging the use of tree order, rather than transitive dependency order, for layout.... Read more
Affected Products : chrome- Published: Nov. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6672
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.... Read more
- Published: Dec. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-6734
Cross-site scripting (XSS) vulnerability in contrib/cssgen.php in the GeSHi, as used in the SyntaxHighlight_GeSHi extension and MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2, allows remote attackers to inject arbitrary web scrip... Read more
Affected Products : mediawiki- Published: Sep. 01, 2015
- Modified: Apr. 12, 2025