Latest CVE Feed
-
4.3
MEDIUMCVE-2006-0023
Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simp... Read more
Affected Products : windows_xp- Published: Feb. 08, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-5767
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765.... Read more
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7886
NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.... Read more
- Published: Jan. 18, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5670
Cross-site scripting (XSS) vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : enisys_gw- Published: Oct. 29, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-7371
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and... Read more
Affected Products : rits_browser- Published: Oct. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-4664
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read photo-directory metadata vi... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2020-7364
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser version 13.0.8 ... Read more
Affected Products : uc_browser- Published: Oct. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3878
Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact a... Read more
Affected Products : imail_server- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2610
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Popup windows.... Read more
Affected Products : e-business_suite- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6858
HP Insight Control server provisioning before 7.5.0 RabbitMQ allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
- Published: Jan. 05, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6852
Directory traversal vulnerability in the API in EMC Secure Remote Services Virtual Edition 3.x before 3.10 allows remote authenticated users to read log files via a crafted parameter.... Read more
Affected Products : secure_remote_services- Published: Dec. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0481
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploade... Read more
- Published: Aug. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2622
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 allows remote attackers to affect integrity via unknown vectors related to Fluid Core.... Read more
Affected Products : peoplesoft_products- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0153
The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.... Read more
- Published: Sep. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-13757
Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.... Read more
- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6784
The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafted URL, as demonstrated by an initial http://example.com?... Read more
Affected Products : chrome- Published: Dec. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6786
The CSPSourceList::matches function in WebKit/Source/core/frame/csp/CSPSourceList.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts a blob:, data:, or filesystem: URL as a match for a * pattern, which all... Read more
Affected Products : chrome- Published: Dec. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6785
The CSPSource::hostMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Google Chrome before 47.0.2526.73 accepts an x.y hostname as a match for a *.x.y pattern, which might allow remote att... Read more
Affected Products : chrome- Published: Dec. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6790
The WebPageSerializerImpl::openTagToString function in WebKit/Source/web/WebPageSerializerImpl.cpp in the page serializer in Google Chrome before 47.0.2526.80 does not properly use HTML entities, which might allow remote attackers to inject arbitrary web ... Read more
Affected Products : chrome- Published: Dec. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6336
The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attackers to cause a denial of service (ap... Read more
Affected Products : wireshark- Published: Nov. 04, 2013
- Modified: Apr. 11, 2025