Latest CVE Feed
-
4.3
MEDIUMCVE-2017-3481
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0 and 12.0.1. Easily "exploitable" vulnerability allows low pr... Read more
Affected Products : flexcube_universal_banking- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-0268
Microsoft Internet Explorer 8 through 11 does not properly restrict file installation and registry-key creation, which allows remote attackers to bypass the Mandatory Integrity Control protection mechanism via a crafted web site, aka "Internet Explorer El... Read more
Affected Products : internet_explorer- Published: Feb. 12, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0124
Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the "Real name" field in Personal Settings, which is presented to readers of articles; or (2) a... Read more
Affected Products : serendipity- Published: Feb. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4681
Unspecified vulnerability in the Bluetooth RFCOMM dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via unknown packets.... Read more
Affected Products : wireshark- Published: Oct. 22, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-2898
Vulnerability in the BI Publisher (formerly XML Publisher) product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low ... Read more
Affected Products : bi_publisher- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-35111
When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked t... Read more
- Published: Jan. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-4008
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a... Read more
Affected Products : ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_eus chrome libxml2 itunes mac_os_x +5 more products- Published: Nov. 17, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6836
Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.... Read more
Affected Products : gnumeric- Published: Dec. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1688
Directory traversal vulnerability in Best Practical Solutions RT 3.2.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote attackers to read arbitrary files via a crafted HTTP request.... Read more
- Published: Apr. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0246
SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitive information by reading the archive.... Read more
Affected Products : sosreport- Published: May. 29, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-18020
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.... Read more
Affected Products : qpdf- Published: Oct. 06, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3324
Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCu... Read more
Affected Products : telepresence_server_software- Published: Jul. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4467
WebKit, as used in Apple iOS before 8.1.3, does not properly determine scrollbar boundaries during the rendering of FRAME elements, which allows remote attackers to spoof the UI via a crafted web site.... Read more
Affected Products : iphone_os- Published: Jan. 30, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3315
Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID C... Read more
Affected Products : unified_communications_manager- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-3183
The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds read.... Read more
Affected Products : libwww- Published: Oct. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5924
Cross-site scripting (XSS) vulnerability in the Web Server (HTTP) task in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.2 FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : lotus_domino- Published: Nov. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-0335
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Serena Dimensions CM 12.2 build 7.199.0 allow remote attackers to inject arbitrary web script or HTML via the (1) DB_CONN, (2) DB_NAME, (3) DM_HOST, (4) MAN_DB_NAME, (5) framecmd, (6... Read more
Affected Products : dimensions_cm- Published: Mar. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4514
Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to the getDebugInfo function.... Read more
Affected Products : alipay- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0295
VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in February 2014, aka "VSAVB... Read more
Affected Products : .net_framework- Published: Feb. 12, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3265
Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuo06900.... Read more
Affected Products : security_manager- Published: May. 20, 2014
- Modified: Apr. 12, 2025