Latest CVE Feed
-
4.3
MEDIUMCVE-2008-6095
Cross-site scripting (XSS) vulnerability in surveillanceView.htm in OpenNMS 1.5.94 allows remote attackers to inject arbitrary web script or HTML via the viewName parameter.... Read more
Affected Products : opennms- Published: Feb. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-1436
Multiple cross-site scripting (XSS) vulnerabilities in UPOINT @1 Event Publisher allow remote attackers to inject arbitrary web script or HTML via the (1) Event, (2) Description, (3) Time, (4) Website, and (5) Public Remarks fields to (a) eventpublisher_a... Read more
Affected Products : at1_event_publisher- Published: Apr. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5142
Cross-site scripting (XSS) vulnerability in buscar.asp in Solidweb Novus 1.0 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from thi... Read more
Affected Products : novus- Published: Sep. 28, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5278
Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a dir... Read more
Affected Products : zomplog- Published: Oct. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2292
CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.... Read more
- Published: Apr. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-0211
IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message.... Read more
- Published: Apr. 28, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-1210
An issue has been discovered in GitLab affecting all versions starting from 12.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to leak a user's email via an error message for g... Read more
Affected Products : gitlab- Published: Aug. 02, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0281
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.... Read more
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-5249
Multiple buffer overflows in the logging function in the Unreal engine, as used by America's Army and America's Army Special Forces 2.8.2 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to cause a denial of service (daemon crash) via ... Read more
- Published: Oct. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-0762
A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins, aka 'Microsoft Browsers Security Feature Bypass Vulnerability'.... Read more
- Published: Apr. 09, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-1234
Inappropriate implementation in Intents in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-3438
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches ... Read more
- Published: Aug. 05, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-2300
Multiple cross-site scripting (XSS) vulnerabilities in Endy Kristanto Surat kabar / News Management Online (aka phpwebnews) 0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the m_txt parameter to (1) iklan.php, (2) index.p... Read more
Affected Products : phpwebnews- Published: Apr. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4692
The tabbed browsing feature in Apple Safari 3 before Beta Update 3.0.4 on Windows, and Mac OS X 10.4 through 10.4.10, allows remote attackers to spoof HTTP authentication for other sites and possibly conduct phishing attacks by causing an authentication s... Read more
- Published: Nov. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4632
Cisco IOS 12.2E, 12.2F, and 12.2S places a "no login" line into the VTY configuration when an administrator makes certain changes to a (1) VTY/AUX or (2) CONSOLE setting on a device without AAA enabled, which allows remote attackers to bypass authenticati... Read more
Affected Products : ios- Published: Aug. 31, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4411
ircu 2.10.12.05 and earlier allows remote attackers to discover the hidden IP address of arbitrary +x users via a series of /silence commands with (1) CIDR mask arguments or (2) certain other arguments that represent groups of IP addresses, then monitorin... Read more
Affected Products : ircu- Published: Aug. 18, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4461
NuFW 2.2.3, and certain other versions after 2.0, allows remote attackers to bypass time-based packet filtering rules via certain "out of period" choices of packet transmission time.... Read more
Affected Products : nufw- Published: Aug. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-2730
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which make... Read more
- Published: Jul. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-4392
Winamp 5.35 allows remote attackers to cause a denial of service (program stack overflow and application crash) via an M3U file that recursively includes itself.... Read more
Affected Products : winamp- Published: Aug. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2235
Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories... Read more
Affected Products : punbb- Published: Apr. 25, 2007
- Modified: Apr. 09, 2025