Latest CVE Feed
-
4.3
MEDIUMCVE-2012-5908
Cross-site scripting (XSS) vulnerability in admin/modules/user/users.php in MyBB (aka MyBulletinBoard) 1.6.6 allows remote attackers to inject arbitrary web script or HTML via the conditions[usergroup][] parameter in a search action to admin/index.php.... Read more
Affected Products : mybb- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4144
Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a cr... Read more
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5917
SnackAmp 3.1.3 allows remote attackers to cause a denial of service (application crash) via a long string in an aiff file.... Read more
Affected Products : snackamp- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4651
Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets from the Scan Safe Tower, aka Bug ID CSCub85451.... Read more
Affected Products : ios- Published: Apr. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-20434
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device. This vulnerability is due to improper handling of frames with VLAN tag i... Read more
Affected Products : ios_xe- Published: Sep. 25, 2024
- Modified: Oct. 08, 2024
-
4.3
MEDIUMCVE-2013-1714
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote at... Read more
- Published: Aug. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5902
Cross-site scripting (XSS) vulnerability in ptk/lib/modal_bookmark.php in DFLabs PTK 1.0.5 allows remote attackers to inject arbitrary web script or HTML via the arg4 parameter.... Read more
Affected Products : ptk- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0719
Cross-site scripting (XSS) vulnerability in IBM Tivoli Endpoint Manager (TEM) 8 before 8.2 patch 3 allows remote attackers to inject arbitrary web script or HTML via the ScheduleParam parameter to the webreports program.... Read more
Affected Products : tivoli_endpoint_manager- Published: Mar. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0715
Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 02, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0707
Cross-site scripting (XSS) vulnerability in IBM WebSphere Lombardi Edition 7.2 allows remote attackers to inject arbitrary web script or HTML via crafted text input to a coach that is configured with a document attachment control section.... Read more
Affected Products : websphere_application_server- Published: Feb. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5911
Cross-site scripting (XSS) vulnerability in blogs/blog1.php in b2evolution 4.1.3 allows remote attackers to inject arbitrary web script or HTML via the message body.... Read more
Affected Products : b2evolution- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0696
Multiple cross-site scripting (XSS) vulnerabilities in the Executive Viewer (EV) in IBM Cognos TM1 before 9.5 FP1 allow remote attackers to inject arbitrary web script or HTML via unspecified requests to (1) aspnet_client or (2) evserver/createcontrol.js.... Read more
- Published: Jan. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-21099
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Data Visualization). The supported version that is affected is 7.0.0.0.0. Easily exploitable vulnerability allows low privileged attacker with n... Read more
Affected Products : business_intelligence- Published: Apr. 16, 2024
- Modified: May. 08, 2025
-
4.3
MEDIUMCVE-2011-3562
Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : fusion_middleware- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3513
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity, related to HTML Pages.... Read more
Affected Products : e-business_suite- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4146
Opera before 12.01 allows remote attackers to cause a denial of service (application crash) via a crafted web site, as demonstrated by the Lenovo "Shop now" page.... Read more
Affected Products : opera_browser- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6043
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.... Read more
- Published: Nov. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0681
Apple Remote Desktop before 3.6.1 does not recognize the "Encrypt all network data" setting during connections to third-party VNC servers, which allows remote attackers to obtain cleartext VNC session content by sniffing the network.... Read more
Affected Products : apple_remote_desktop- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3428
The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers t... Read more
Affected Products : ironjacamar- Published: Dec. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5913
Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.... Read more
- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025