Latest CVE Feed
-
4.3
MEDIUMCVE-2010-2091
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive informa... Read more
- Published: May. 27, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2106
Unspecified vulnerability in Google Chrome before 5.0.375.55 might allow remote attackers to spoof the URL bar via vectors involving unload event handlers.... Read more
Affected Products : chrome- Published: May. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-5119
The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network ... Read more
- Published: Aug. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2111
Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action.... Read more
Affected Products : pacific_timesheet- Published: May. 28, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1095
Cross-site scripting (XSS) vulnerability in login_reset_password_page.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: the provenance of this ... Read more
Affected Products : truc- Published: Mar. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4403
Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : rumba_xml- Published: Dec. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2154
Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: some of these details are obtained from third party i... Read more
Affected Products : cmscout- Published: Jun. 03, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4384
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web script or HTML via the (1) pid parameter in a code action to index.php and the (2) uid parameter in a view action to p... Read more
Affected Products : ez_poll_hoster- Published: Dec. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1091
Multiple cross-site scripting (XSS) vulnerabilities in contact.php in phpMySite allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) city, (3) email, (4) state, and (5) message parameters.... Read more
Affected Products : phpmysite- Published: Mar. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2119
Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid nntp:// URIs.... Read more
Affected Products : internet_explorer- Published: Jun. 01, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-5149
Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have predictable technician passwords, which makes it easier for remote attackers to obtain access via the web management interface, related to a "password o... Read more
- Published: Nov. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-1074
Cross-site scripting (XSS) vulnerability in the Currency Exchange module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to watchdog logging.... Read more
- Published: Mar. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2130
Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.... Read more
Affected Products : arisg- Published: Jun. 02, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4388
Cross-site scripting (XSS) vulnerability in the ListMan (nl_listman) extension 1.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4397
Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Dec. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2118
Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.... Read more
- Published: Jun. 01, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2117
Mozilla Firefox 3.0.19, 3.5.x, and 3.6.x allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.... Read more
Affected Products : firefox- Published: Jun. 01, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4381
Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inject arbitrary web script or HTML via the pa parameter. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : million_pixel_script- Published: Dec. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-14577
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticat... Read more
Affected Products : ubuntu_linux fedora debian_linux leap active_iq_unified_manager cloud_backup oncommand_insight oncommand_workflow_automation jdk jre +10 more products- Published: Jul. 15, 2020
- Modified: May. 27, 2025
-
4.3
MEDIUMCVE-2009-2958
The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.... Read more
Affected Products : dnsmasq- Published: Sep. 02, 2009
- Modified: Apr. 09, 2025