Latest CVE Feed
-
4.3
MEDIUMCVE-2018-0939
ChakraCore and Microsoft Edge in Windows 10 1703 and 1709 allow information disclosure, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0891.... Read more
- Published: Mar. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2357
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "IOAudioFamily" component. It allows attackers to obtain sensitive kernel memory-layout information via a crafted app.... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-3033
Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have a memory address leak vulnerability when handling JPEG 2000 code-stream tile data.... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-3696
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table.... Read more
Affected Products : phpmyadmin- Published: Oct. 16, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-5214
Google Chrome prior to 55.0.2883.75 for Windows mishandled downloaded files, which allowed a remote attacker to prevent the downloaded file from receiving the Mark of the Web via a crafted HTML page.... Read more
Affected Products : chrome- Published: Jan. 19, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-3627
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.... Read more
Affected Products : html-parser- Published: Oct. 29, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-1000195
A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins submit a HTTP GET request to an arbitrary URL and learn whet... Read more
- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0584
Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0579, CVE-20... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2711
Cross-site scripting (XSS) vulnerability in J-Web in Juniper Junos before 11.4R11, 11.4X27 before 11.4X27.62 (BBE), 12.1 before 12.1R9, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.2 before 12.2R7, 12.3 before 12.... Read more
- Published: Apr. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-3550
The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace. NOTE: some of these... Read more
Affected Products : wireshark- Published: Oct. 30, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-1357
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to manipulate work orders to forge emails which could be used to conduct further advanced attacks. IBM X-Force ID: 126684.... Read more
Affected Products : maximo_application_suite maximo_asset_management maximo_asset_management_essentials- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-3263
Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML ... Read more
Affected Products : chrome- Published: Sep. 18, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-3343
Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (DHCPv6 daemon crash) via a malformed DHCPv6 packet, aka Bug ID CSCuo59052.... Read more
Affected Products : ios_xr- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-1377
IBM Runbook Automation reveals sensitive information in error messages that could be used in further attacks against the system. IBM X-Force ID: 126874.... Read more
Affected Products : runbook_automation- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-2017
Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with net... Read more
- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3616
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host... Read more
- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-45323
An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organiz... Read more
Affected Products : fortiedrmanager- Published: Sep. 10, 2024
- Modified: Sep. 20, 2024
-
4.3
MEDIUMCVE-2017-1497
IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing they know the directory location of the file. IBM X-Force ID: 128695.... Read more
Affected Products : sterling_file_gateway- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-2373
Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : drupal- Published: Jul. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-1412
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 127400.... Read more
Affected Products : security_identity_governance_and_intelligence- Published: Aug. 06, 2018
- Modified: Nov. 21, 2024