Latest CVE Feed
-
4.3
MEDIUMCVE-2013-1881
GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.... Read more
Affected Products : librsvg- Published: Oct. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3826
Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in register.ph... Read more
Affected Products : boastmachine- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-4307
A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12, Safari 12.... Read more
- Published: Apr. 03, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2005-4663
Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.... Read more
Affected Products : ocomon- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-0069
Cross-site scripting (XSS) vulnerability in addentry.php in Chipmunk Guestbook 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.... Read more
Affected Products : chipmunk_guestbook- Published: Jan. 03, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-2785
The extensions implementation in Google Chrome before 13.0.782.107 does not properly validate the URL for the home page, which allows remote attackers to have an unspecified impact via a crafted extension.... Read more
Affected Products : chrome- Published: Aug. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3818
Cross-site scripting (XSS) vulnerability in the login page in Novell GroupWise WebAccess 6.5 before 20060721 and WebAccess 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via the GWAP.version parameter.... Read more
Affected Products : groupwise_webaccess- Published: Aug. 11, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-1928
The fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library 1.4.3 and 1.4.4, and the Apache HTTP Server 2.2.18, allows remote attackers to cause a denial of service (infinite loop) via a URI that does not match unspecified typ... Read more
- Published: May. 24, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-7764
The vulnerability exists within runscript.php applet in Schneider Electric U.motion Builder software versions prior to v1.3.4. There is a directory traversal vulnerability in the processing of the 's' parameter of the applet.... Read more
Affected Products : u.motion_builder- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4314
The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted ce... Read more
- Published: Sep. 30, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2361
The Basic Authentication dialog implementation in Google Chrome before 13.0.782.107 does not properly handle strings, which might make it easier for remote attackers to capture credentials via a crafted web site.... Read more
Affected Products : chrome- Published: Aug. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3918
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in... Read more
Affected Products : ubuntu_linux debian_linux enterprise_linux_server enterprise_linux_workstation http_server- Published: Jul. 28, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4551
Cross-site scripting (XSS) vulnerability in sign.php in codegrrl SimpBook 1.0, when html_enable is on, allows remote attackers to inject arbitrary web script or HTML via the message parameter to index.php.... Read more
Affected Products : simpbook- Published: Dec. 28, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-2191
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.... Read more
- Published: Feb. 08, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6050
Integer overflow in Links before 2.8 allows remote attackers to cause a denial of service (crash) via crafted HTML tables.... Read more
Affected Products : links- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-1603
Multiple cross-site scripting (XSS) vulnerabilities in Adminsystems CMS before 4.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to index.php or (2) id parameter in a users_users action to asys/site/system.php.... Read more
Affected Products : adminsystems_cms- Published: Feb. 19, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8371
VMware vCenter Server Appliance (vCSA) 5.5 before Update 2, 5.1 before Update 3, and 5.0 before Update 3c does not properly validate certificates when connecting to a CIM Server on an ESXi host, which allows man-in-the-middle attackers to spoof CIM server... Read more
Affected Products : vcenter_server_appliance- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1458
The Microsoft CHM file parser in ClamAV 0.96.4 and Sophos Anti-Virus 4.61.0 allows remote attackers to bypass malware detection via a crafted reset interval in the LZXC header of a CHM file. NOTE: this may later be SPLIT into multiple CVEs if additional ... Read more
- Published: Mar. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-34765
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists because proper role-b... Read more
Affected Products : nexus_insights- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2025-46388
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor... Read more
Affected Products :- Published: Aug. 06, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Information Disclosure