Latest CVE Feed
-
4.3
MEDIUMCVE-2013-5181
The auto-configuration feature in Mail in Apple Mac OS X before 10.9 selects plaintext authentication for unspecified servers that support CRAM-MD5 authentication, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more
- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5129
Multiple cross-site scripting (XSS) vulnerabilities in WebKit in Apple iOS before 7 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.... Read more
Affected Products : iphone_os- Published: Sep. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5095
Cross-site scripting (XSS) vulnerability in the web-based interface in Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka ... Read more
- Published: Aug. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-17926
The product M2M ETHERNET (FW Versions 2.22 and prior, ETH-FW Versions 1.01 and prior) is vulnerable in that an attacker can upload a malicious language file by bypassing the user authentication mechanism.... Read more
- Published: Jan. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-5057
hxds.dll in Microsoft Office 2007 SP3 and 2010 SP1 and SP2 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted COM component on a web site that is visited with Internet Explo... Read more
Affected Products : office- Published: Dec. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5006
main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware 1.05.12, 1.06.18, and 1.06.28, allows remote attackers to discover the cleartext administrative password by reading the "... Read more
- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2002-2129
Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary web script via an arbitrary form field name containing the script, which is echoed back to the user when displaying the form.... Read more
Affected Products : w-agora- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-1690
Best Practical Solutions RT 3.6.0 through 3.6.10 and 3.8.0 through 3.8.8 allows remote attackers to trick users into sending credentials to an arbitrary server via unspecified vectors.... Read more
- Published: Apr. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1712
The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potent... Read more
- Published: Apr. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1726
Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : sitescope- Published: May. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1176
The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, which mig... Read more
- Published: Mar. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5482
Cisco Prime LAN Management Solution (LMS) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripti... Read more
Affected Products : prime_lan_management_solution- Published: Sep. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2025-46708
Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.... Read more
Affected Products : ddk- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2011-1819
Google Chrome before 12.0.742.91 allows remote attackers to perform unspecified injection into a chrome:// page via vectors related to extensions.... Read more
Affected Products : chrome- Published: Jun. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1829
APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.... Read more
- Published: Jul. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-17859
An issue was discovered in Joomla! before 3.8.13. Inadequate checks in com_contact could allow mail submission in disabled forms.... Read more
Affected Products : joomla\!- Published: Oct. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4670
Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Aug. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4649
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.... Read more
Affected Products : dotnetnuke- Published: Mar. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-1077
Multiple cross-site scripting (XSS) vulnerabilities in Apache Archiva 1.0 through 1.2.2, and 1.3.x before 1.3.5, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : archiva- Published: Jun. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5573
Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field in the user configuration.... Read more
Affected Products : jenkins- Published: Dec. 31, 2013
- Modified: Apr. 11, 2025