Latest CVE Feed
-
4.3
MEDIUMCVE-2014-0463
Unspecified vulnerability in Oracle Java SE 8 allows remote attackers to affect confidentiality via unknown vectors related to Scripting, a different vulnerability than CVE-2014-0464.... Read more
- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-3634
Cross-site scripting (XSS) vulnerability in the Frontend Login Box (aka felogin) subcomponent in TYPO3 4.2.0 through 4.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : typo3- Published: Nov. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3641
Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol.... Read more
Affected Products : snort- Published: Oct. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-0390
Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect integrity via unknown vectors related to Java Web Console.... Read more
- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0564
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administra... Read more
Affected Products : mailman- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-2937
Inappropriate implementation in Picture In Picture in Google Chrome prior to 114.0.5735.90 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severi... Read more
- Published: May. 30, 2023
- Modified: Mar. 11, 2025
-
4.3
MEDIUMCVE-2014-0855
Multiple cross-site scripting (XSS) vulnerabilities in IBM Connections Portlets 4.x before 4.5.1 FP1 for IBM WebSphere Portal 7.0.0.2 and 8.0.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 14, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0806
The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for Android provide Geolocation API data without verifying user consent, which allows remote attackers to obtain sensitive location informa... Read more
Affected Products : sleipnir_mobile- Published: Jan. 22, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-3440
Multiple cross-site scripting (XSS) vulnerabilities in the administrative web interface in Cisco Unified Operations Manager allow remote attackers to inject arbitrary web script or HTML, and obtain improperly secured cookies, via unspecified vectors, aka ... Read more
Affected Products : unified_operations_manager- Published: Jul. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-7419
Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the roomid parameter... Read more
Affected Products : js_multi_hotel- Published: Jan. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-21383
Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Log). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows low privileged attacker with network access v... Read more
Affected Products : enterprise_session_border_controller- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0828
Cross-site scripting (XSS) vulnerability in the WCM (Web Content Manager) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF11 allows remote attackers to injec... Read more
Affected Products : websphere_portal- Published: Apr. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0445
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect integrity via vectors related to PIA Core Technology, a different vulnerability than CVE-2014-0381.... Read more
Affected Products : peoplesoft_products- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6169
The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack.... Read more
Affected Products : ejabberd- Published: Oct. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-3422
Cross-site scripting (XSS) vulnerability in Administration pages in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75165.... Read more
Affected Products : secure_access_control_system- Published: Jul. 12, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0852
IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sen... Read more
- Published: Aug. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0006
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.... Read more
Affected Products : swift- Published: Jan. 23, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0827
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Workload Replay 1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : optim_workload_replay- Published: Apr. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-3024
The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard is used, which allows remote attackers to bypass the hostname check for a ... Read more
Affected Products : io-socket-ssl- Published: Aug. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-7436
noVNC before 0.5 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.... Read more
Affected Products : novnc- Published: Apr. 10, 2015
- Modified: Apr. 12, 2025