Latest CVE Feed
-
4.3
MEDIUMCVE-2009-2687
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.... Read more
- Published: Aug. 05, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3025
Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.... Read more
Affected Products : pidgin- Published: Aug. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2748
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.29 and 7.1 before 7.0.0.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_application_server- Published: Oct. 30, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2696
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary... Read more
- Published: Aug. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-4939
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdPeeps 8.5d1 allow remote attackers to inject arbitrary web script or HTML via the (1) uid parameter, (2) uid parameter in a login_lookup action, (3) uid parameter in an adminlogin actio... Read more
Affected Products : adpeeps- Published: Jul. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2684
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Produc... Read more
Affected Products : laserjet_2410 laserjet_2420 color_laserjet_4730_mfp laserjet_4240 laserjet_4345_mfp laserjet_9050_mfp laserjet_m3027_mfp laserjet_m3035_mfp laserjet_m5025_mfp laserjet_p4014 +25 more products- Published: Oct. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2738
Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.... Read more
Affected Products : freenas- Published: Aug. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2655
mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additi... Read more
- Published: Aug. 03, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2595
Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.... Read more
Affected Products : censura- Published: Jul. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2586
Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitrary web script or HTML via the title parameter.... Read more
Affected Products : ezarticles- Published: Jul. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2569
Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.htm... Read more
Affected Products : verlihub_control_panel- Published: Jul. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2594
Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the itemid parameter in a details action.... Read more
Affected Products : censura- Published: Jul. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-11341
The Simple Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to missing or incorrect nonce validation on the settings_page() function. This makes it possible for unauthentic... Read more
Affected Products :- Published: Dec. 05, 2024
- Modified: Dec. 05, 2024
-
4.3
MEDIUMCVE-2009-2581
Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : esnews- Published: Jul. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4926
Multiple cross-site scripting (XSS) vulnerabilities in Online Contact Manager (formerly EContact PRO) 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) showGroup parameter to (a) index.php and the (2) id parameter to (b) view.p... Read more
Affected Products : online_contact_manager- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2613
Multiple cross-site scripting (XSS) vulnerabilities in DataCheck Solutions LinkPal 1.x allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) z_loginfailed.asp, (2) z_admin_login.asp, (3) z_forgot.asp, and possibly uns... Read more
Affected Products : linkpal- Published: Jul. 27, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2587
Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search paramet... Read more
Affected Products : dragdropcart- Published: Jul. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2700
src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers... Read more
Affected Products : qt- Published: Sep. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2739
Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : freenas- Published: Aug. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4924
Dan Pascu python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.... Read more
Affected Products : python-cjson- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025