Latest CVE Feed
-
4.3
MEDIUMCVE-2014-5382
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Schrack Technik microControl with firmware 1.7.0 (937) allow remote attackers to inject arbitrary web script or HTML via the position textbox in the configuration menu or other un... Read more
- Published: Aug. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2582
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and 3.1.x before 3.1.6, allow remote... Read more
- Published: Aug. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5604
The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote attackers to bypass authentication via unspecified vectors.... Read more
- Published: Mar. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1998
Cross-site scripting (XSS) vulnerability in Nippon Institute of Agroinformatics SOY CMS 1.4.0c and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : soy_cms- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-1030
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPress MU (WPMU) before 2.7 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.... Read more
Affected Products : wordpress_mu- Published: Mar. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-3681
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5259
Cross-site scripting (XSS) vulnerability in cattranslate.php in the CatTranslate JQuery plugin in BlackCat CMS 1.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg parameter.... Read more
Affected Products : blackcat_cms- Published: Sep. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-2433
An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which preven... Read more
- Published: Mar. 13, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-5341
The SFTP external storage driver (files_external) in ownCloud Server before 6.0.5 validates the RSA Host key after login, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more
Affected Products : owncloud- Published: Feb. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-1885
Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "... Read more
Affected Products : xerces-c\+\+- Published: Aug. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-5234
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via a folder publication name.... Read more
Affected Products : open-xchange_appsuite- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-5257
Multiple cross-site scripting (XSS) vulnerabilities in Forma Lms before 1.2.1 p01 allow remote attackers to inject arbitrary web script or HTML via the (1) id_custom parameter in an amanmenu request or (2) id_game parameter in an alms/games/edit request t... Read more
Affected Products : formalms- Published: Nov. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-2869
The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a su... Read more
Affected Products : firefox- Published: Jun. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-5065
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas.... Read more
Affected Products : feedparser- Published: Apr. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-5348
Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.... Read more
Affected Products : steelapp_traffic_manager- Published: Aug. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3601
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or... Read more
- Published: Sep. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4820
Cross-site scripting (XSS) vulnerability in IBM Integration Bus Manufacturing Pack 1.x before 1.0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : integration_bus_manufacturing_pack- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-3264
The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit to a... Read more
Affected Products : chrome- Published: Sep. 18, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-4810
IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between the Cognos Mobile server and the Cognos Business Intelligence server after a logoff action on a mobile device, which makes it easier for ... Read more
Affected Products : cognos_mobile- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-0161
The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of ser... Read more
- Published: Mar. 23, 2010
- Modified: Apr. 11, 2025