Latest CVE Feed
-
4.3
MEDIUMCVE-2007-6409
The gg protocol handler in Gadu-Gadu, when this product is installed but not running, does not properly handle the skin attribute, which allows remote attackers to cause a denial of service (resource consumption) via unspecified network traffic.... Read more
Affected Products : gadu-gadu_instant_messenger- Published: Dec. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-3962
Cross-site scripting (XSS) vulnerability in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models before firmware 1.0.4.44, allows remote attackers to ... Read more
Affected Products : gxv_device_firmware gxv3500 gxv3501 gxv3504 gxv3601 gxv3601hd\/ll gxv3611hd\/ll gxv3615w\/p gxv3615wp_hd gxv3651fhd +1 more products- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-5192
Cross-site scripting (XSS) vulnerability in pretty-bar.php in Pretty Link Lite plugin before 1.5.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter, a different vulnerability than CVE-2011-5191.... Read more
- Published: Sep. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4631
Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to inject arbitrary web script or HTML via the (1) countrycode parameter to contact.asp, USERNAME parameter to (2) gateway.asp and (3) cart.asp, and the s... Read more
Affected Products : pilot_cart- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-1220
Cybozu Garoon before 4.2.2 does not properly restrict access.... Read more
Affected Products : garoon- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2011-5207
Cross-site scripting (XSS) vulnerability in admin/OptionsPostsList.php in the TheCartPress plugin for WordPress before 1.1.6 before 2011-12-31 allows remote attackers to inject arbitrary web script or HTML via the tcp_name_post_XXXXX parameter.... Read more
- Published: Oct. 04, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-4630
Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
- Published: Dec. 30, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-4743
IBM Financial Transaction Manager 3.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The... Read more
- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4234
IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacker by intercepting the subsequent requests can bypass business logic to modify the pattern to unlocked state. IBM X-Force ID: ... Read more
Affected Products : pureapplication_system- Published: Jun. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0238
IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 110409... Read more
Affected Products : security_guardium- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-4045
Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : spss_collaboration_and_deployment_services- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-3003
details.php in Easy Ad-Manager allows remote attackers to obtain the full installation path via an invalid mbid parameter, which leaks the path in an error message. NOTE: this might be resultant from another vulnerability, since this vector also produces... Read more
Affected Products : easy_ad-manager- Published: Jun. 13, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3087
Multiple cross-site scripting (XSS) vulnerabilities in EZGallery 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) pUserID, (2) aid, (3) aname, (4) uid, and (5) m parameter in (a) common/galleries.asp; (6) aid, (7) ... Read more
Affected Products : ezgallery- Published: Jun. 19, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-8898
An information disclosure issue existed in the handling of the Storage Access API. This issue was addressed with improved logic. This issue is fixed in iOS 13.3 and iPadOS 13.3, tvOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows. Visiting a maliciously ... Read more
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-1368
CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into... Read more
Affected Products : internet_explorer- Published: Mar. 18, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6645
Cross-site scripting (XSS) vulnerability in Opencosmo VisualSentinel 0.7 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header ($_SERVER ['HTTP_USER_AGENT']), which is not properly handled when displaying log files.... Read more
Affected Products : visualsentinel- Published: Apr. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3074
Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.... Read more
Affected Products : firefox- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5427
Norton Antivirus in Norton Internet Security 15.5.0.23 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to c... Read more
Affected Products : norton_internet_security_2008- Published: Dec. 11, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-7892
The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : adstxt- Published: Sep. 25, 2024
- Modified: Oct. 07, 2024
-
4.3
MEDIUMCVE-2009-4991
Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to inject arbitrary web script or HTML via the job2 parameter.... Read more
Affected Products : omnistar_recruiting- Published: Aug. 25, 2010
- Modified: Apr. 11, 2025