Latest CVE Feed
-
4.3
MEDIUMCVE-2011-2360
Google Chrome before 13.0.782.107 does not ensure that the user is prompted before download of a dangerous file, which makes it easier for remote attackers to bypass intended content restrictions via a crafted web site.... Read more
Affected Products : chrome- Published: Aug. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3760
Cross-site scripting (XSS) vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to inject arbitrary web script or HTML via frame tags.... Read more
- Published: Sep. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2301
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element.... Read more
- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2022-0746
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.... Read more
Affected Products : dolibarr_erp\/crm- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-31745
If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101.... Read more
Affected Products : firefox- Published: Dec. 22, 2022
- Modified: Apr. 15, 2025
-
4.3
MEDIUMCVE-2012-3413
The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.... Read more
Affected Products : kde_pim- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3414
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName ... Read more
- Published: Jul. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-3127
Vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite (subcomponent: Product Security). Supported versions that are affected are 7.3.5 and 12.2. Easily exploitable vulnerability allows unauthenticated attac... Read more
Affected Products : demantra_demand_management- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-3555
Cross-site scripting (XSS) vulnerability in index.php in Moodle 1.7.1 allows remote attackers to inject arbitrary web script or HTML via a style expression in the search parameter, a different vulnerability than CVE-2004-1424.... Read more
Affected Products : moodle- Published: Jul. 04, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2325
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL in... Read more
- Published: Jun. 18, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3219
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for D... Read more
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2429
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.1.2, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer in a "404 Not Found" response.... Read more
- Published: Jun. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6054
Cross-site scripting (XSS) vulnerability in the login page in the management interface in the Aruba 800 Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier, allows remote attackers to inject arbitrary web script or HTML via the PATH_INF... Read more
Affected Products : mc-800- Published: Nov. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-5882
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208.... Read more
Affected Products : yui- Published: Nov. 16, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3101
Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to t... Read more
Affected Products : myfaces_tomahawk- Published: Jun. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2543
Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script or HTML via the graph_start parameter to graph.php. NOTE: this vulnerability exists because of an incor... Read more
Affected Products : cacti- Published: Aug. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3008
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.... Read more
- Published: Jun. 04, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-2133
Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 8 and 9 before 9.0.1.262, and RoboHelp Server 8 and 9, allows remote attackers to inject arbitrary web script or HTML via the URI, related to template_stock/whutils.js.... Read more
- Published: Aug. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0904
VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file.... Read more
Affected Products : vlc_media_player- Published: Jan. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-11567
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an addition... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024