Latest CVE Feed
-
4.3
MEDIUMCVE-2007-0801
The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.... Read more
Affected Products : firefox- Published: Feb. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-6331
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is ca... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1765
Microsoft Internet Explorer 9 through 11 allows remote attackers to read the browser history via a crafted web site.... Read more
Affected Products : internet_explorer- Published: Jun. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-0616
Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (... Read more
Affected Products : postnuke_phoenix- Published: Feb. 28, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-5916
The Apple Pay component in Apple iOS before 9 allows remote terminals to obtain sensitive recent-transaction information during payments by leveraging the transaction-log feature.... Read more
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4347
Cross-site scripting (XSS) vulnerability in the inLinks Integration module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified path arguments.... Read more
Affected Products : inlinks- Published: Jun. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-0563
Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("javAsc
ript:") ... Read more
Affected Products : exchange_server- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-4546
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is... Read more
Affected Products : flash_player- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5511
Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "un... Read more
- Published: Dec. 17, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7274
IBM WebSphere Application Server (WAS) 6.1.0.9, when the JAAS Login functionality is enabled, allows attackers to perform an internal application hashtable login by (1) not providing a password or (2) providing an empty password.... Read more
Affected Products : websphere_application_server- Published: Feb. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-6241
The proto_tree_add_bytes_item function in epan/proto.c in the protocol-tree implementation in Wireshark 1.12.x before 1.12.7 does not properly terminate a data structure after a failure to locate a number within a string, which allows remote attackers to ... Read more
- Published: Aug. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-6762
Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.... Read more
Affected Products : wordpress- Published: Apr. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-8122
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.... Read more
Affected Products : nextcloud_server- Published: Feb. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5768
AppleGraphicsControl in Apple OS X before 10.10.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.... Read more
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6265
The CLI in Cisco Application Control Engine (ACE) 4700 A5 3.0 and earlier allows local users to bypass intended access restrictions, and read or write to files, by entering an unspecified CLI command with a crafted file as this command's input, aka Bug ID... Read more
Affected Products : application_control_engine_4700- Published: Aug. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-0144
CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connecti... Read more
- Published: May. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-5272
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2003-0053
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an e... Read more
- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-8166
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF token.... Read more
- Published: Jul. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-0781
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web ... Read more
Affected Products : tomcat- Published: Mar. 09, 2009
- Modified: Apr. 09, 2025