Latest CVE Feed
-
4.3
MEDIUMCVE-2018-18020
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.... Read more
Affected Products : qpdf- Published: Oct. 06, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6415
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the uni... Read more
- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3295
IBM WebSphere MQ 7.1, when an SVRCONN channel is used, allows remote attackers to bypass the security-configuration setup step and obtain queue-manager access via unspecified vectors.... Read more
Affected Products : websphere_mq- Published: Aug. 29, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-27755
in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size. The patch resets the depth to a ... Read more
Affected Products : imagemagick- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3180
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."... Read more
- Published: Sep. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-27758
A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long`. This would most likely lead to ... Read more
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3299
RealNetworks RealPlayer 16.0.2.32 and earlier allows remote attackers to cause a denial of service (resource consumption or application crash) via an HTML document containing JavaScript code that constructs a long string.... Read more
Affected Products : realplayer- Published: Jul. 06, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6395
Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.... Read more
Affected Products : ganglia-web- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-7365
Cross-site scripting (XSS) vulnerability in SAP Enterprise Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : enterprise_portal- Published: Apr. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6454
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via a -o-link attribute.... Read more
Affected Products : mediawiki- Published: May. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6388
Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.... Read more
Affected Products : drupal- Published: Dec. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6327
Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1 and 1.4 before 1.4.0.0 iFix 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cr... Read more
Affected Products : sterling_connect_enterprise_http_option- Published: Dec. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-24434
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this v... Read more
- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-3179
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."... Read more
- Published: Sep. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4208
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.8.1, as used in Bugzilla, Moodle, and other products, allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader/asse... Read more
- Published: Nov. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-0931
Cross-site scripting (XSS) vulnerability in the tag cloud search script (horde/services/portal/cloud_search.php) in Horde before 3.2.4 and 3.3.3, and Horde Groupware before 1.1.5, allows remote attackers to inject arbitrary web script or HTML via unspecif... Read more
- Published: Mar. 17, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-0157
Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description... Read more
- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5766
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.2 and 12.1.0.3 allows... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-1692
Microsoft Internet Explorer 7 through 11 allows user-assisted remote attackers to read the clipboard contents via crafted web script, aka "Internet Explorer Clipboard Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-3818
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via unknown vectors related to Portal, a different vulnerability than CVE-2013-2404... Read more
Affected Products : peoplesoft_products- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025