Latest CVE Feed
-
4.3
MEDIUMCVE-2016-1617
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply w... Read more
Affected Products : chrome- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-4842
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.... Read more
Affected Products : mailwise- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-3649
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated administrators to enumerate administrator accounts via modified GET requests.... Read more
Affected Products : endpoint_protection_manager- Published: Jun. 30, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-4887
The dl function in PHP 5.2.4 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long string in the library parameter. NOTE: there are limited usage scenarios under which this would be a vulnerability.... Read more
Affected Products : php- Published: Sep. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4696
Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to "page transitions" in Safari.... Read more
- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-3452
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to S... Read more
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2002-1700
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filt... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-4911
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.... Read more
- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-4910
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.... Read more
Affected Products : garoon- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2010-3177
Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) file o... Read more
- Published: Oct. 21, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-6024
IBM Jazz technology based products might divulge information that might be useful in helping attackers through error messages. IBM X-Force ID: 116868.... Read more
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2025-8579
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2022-2619
Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.... Read more
- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-1616
The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.... Read more
Affected Products : chrome- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-6430
Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address whe... Read more
- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2004-0203
Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.... Read more
Affected Products : exchange_server- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-3263
Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.... Read more
Affected Products : phpmyadmin- Published: Sep. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-11117
Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Nov. 12, 2024
- Modified: Jan. 02, 2025
-
4.3
MEDIUMCVE-2002-1276
An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-39920
The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of one TCP connection from a client system (to any server), when that client system is concurrently obtaining TCP data at a slow rate fro... Read more
Affected Products :- Published: Jul. 03, 2024
- Modified: Nov. 21, 2024