Latest CVE Feed
-
4.3
MEDIUMCVE-2013-2203
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.... Read more
Affected Products : wordpress- Published: Jul. 08, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0152
SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unspecified telnet options, which triggers a NULL pointer dereference. NOTE: the crash is not user-assist... Read more
Affected Products : slnet_rf_telnet_server- Published: Jan. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-0681
Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via a report containing a crafted URL that is not properly handled during generation of... Read more
Affected Products : identity_services_engine_software- Published: Jan. 29, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-52544
Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Apr. 08, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2010-1724
Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php,... Read more
Affected Products : zikula_application_framework- Published: May. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-18179
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even ... Read more
- Published: Jan. 06, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-0186
Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144.... Read more
Affected Products : netrisk- Published: Jan. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1640
Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.... Read more
Affected Products : clamav- Published: May. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1619
Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or... Read more
Affected Products : moodle- Published: Apr. 29, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0197
Multiple cross-site scripting (XSS) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wpcf_email, (2) wpcf_... Read more
Affected Products : wp-contactform- Published: Jan. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0330
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).... Read more
Affected Products : gallery- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-4816
Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via unknown vectors.... Read more
- Published: Nov. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1455
The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file.... Read more
- Published: May. 12, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2545
Multiple cross-site scripting (XSS) vulnerabilities in Cacti before 0.8.7g, as used in Red Hat High Performance Computing (HPC) Solution and other products, allow remote attackers to inject arbitrary web script or HTML via (1) the name element in an XML t... Read more
Affected Products : cacti- Published: Aug. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-10344
Missing permission checks in Jenkins Configuration as Code Plugin 1.24 and earlier in various HTTP endpoints allowed users with Overall/Read access to access the generated schema and documentation for this plugin containing detailed information about inst... Read more
Affected Products : configuration_as_code- Published: Jul. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-4821
Adobe Flash Player 9.0.124.0 and earlier, when a Mozilla browser is used, does not properly interpret jar: URLs, which allows attackers to obtain sensitive information via unknown vectors.... Read more
- Published: Nov. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1390
Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via vectors related to improper UTF-7 ... Read more
- Published: Jun. 11, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1406
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTT... Read more
- Published: Jun. 11, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4832
Android OS before 2.2 does not display the correct SSL certificate in certain cases, which might allow remote attackers to spoof trusted web sites via a web page containing references to external sources in which (1) the certificate of the last loaded res... Read more
Affected Products : android- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-0178
Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the User-Agent HTTP header.... Read more
Affected Products : liferay_enterprise_portal- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025