Latest CVE Feed
-
4.3
MEDIUMCVE-2011-3827
The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics atta... Read more
Affected Products : groupwise- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-7364
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of UCWeb's UC Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects UCWeb's UC Browser version 13.0.8 ... Read more
Affected Products : uc_browser- Published: Oct. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-3256
FreeType 2 before 2.4.7, as used in CoreGraphics in Apple iOS before 5, Mandriva Enterprise Server 5, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font, a dif... Read more
Affected Products : iphone_os- Published: Oct. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2943
The irc_msg_who function in msgs.c in the IRC protocol plugin in libpurple 2.8.0 through 2.9.0 in Pidgin before 2.10.0 does not properly validate characters in nicknames, which allows user-assisted remote attackers to cause a denial of service (NULL point... Read more
- Published: Aug. 29, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2885
IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via the sample .doc document that incorporates a user-defined toolbar.... Read more
Affected Products : lotus_symphony- Published: Jul. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2888
IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application hang) via complex graphics in a presentation.... Read more
Affected Products : lotus_symphony- Published: Jul. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2782
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.... Read more
- Published: Aug. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2804
Google Chrome before 13.0.782.107 does not properly handle nested functions in PDF documents, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.... Read more
Affected Products : chrome- Published: Aug. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-7371
User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as presented in the browser. This issue affects the RITS Browser version 3.3.9 and... Read more
Affected Products : rits_browser- Published: Oct. 20, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5767
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765.... Read more
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2004-1537
Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter.... Read more
Affected Products : phpkit- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1645
Cross-site scripting (XSS) vulnerability in Xedus 1.0 allows remote attackers to execute arbitrary web script or HTML via the (1) username parameter to test.x, (2) username parameter to TestServer.x, or (3) param parameter to testgetrequest.x.... Read more
Affected Products : xedus- Published: Aug. 30, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-2314
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors related to JavaServer Pages.... Read more
Affected Products : fusion_middleware- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2433
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerabilit... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1958
Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Diameter dictionary file.... Read more
Affected Products : wireshark- Published: Jun. 06, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2609
Opera before 11.50 does not properly restrict data: URIs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.... Read more
Affected Products : opera_browser- Published: Jul. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0781
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) message, (2) pagename, and (3) target filenames.... Read more
- Published: Feb. 14, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-6138
Microsoft Internet Explorer 8 through 11 mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Internet Explorer XSS Filter Bypass Vulnerabilit... Read more
Affected Products : internet_explorer- Published: Dec. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-6611
Cross-site scripting (XSS) vulnerability in view.php in Mantis before 1.1.0 allows remote attackers to inject arbitrary web script or HTML via a filename, related to bug_report.php.... Read more
Affected Products : mantis- Published: Jan. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6286
Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent req... Read more
Affected Products : tomcat- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025