Latest CVE Feed
-
4.3
MEDIUMCVE-2009-2351
Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of... Read more
Affected Products : opera_browser- Published: Jul. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3978
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large i... Read more
Affected Products : firefox- Published: Nov. 19, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2440
Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : guestbook- Published: Jul. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2587
Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search paramet... Read more
Affected Products : dragdropcart- Published: Jul. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2700
src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers... Read more
Affected Products : qt- Published: Sep. 02, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2739
Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : freenas- Published: Aug. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2292
Cross-site scripting (XSS) vulnerability in Appleple a-News 2.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : a-news- Published: Jul. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4640
Array index error in vorbis_dec.c in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Vorbis file that triggers an out-of-bounds read.... Read more
Affected Products : ffmpeg- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2565
Cross-site scripting (XSS) vulnerability in Perl CGI's By Mrs. Shiromuku shiromuku(fs6)DIARY 2.40 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : shiromuku\(fs6\)diary- Published: Jul. 21, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2551
Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script or HTML via the id parameter in a detail action to (1) main.php and possibly (2) demo_page.php.... Read more
Affected Products : easy_image_downloader- Published: Jul. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2537
KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.... Read more
Affected Products : konqueror- Published: Jul. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-21625
Jenkins CloudBees AWS Credentials Plugin 1.28 and earlier does not perform a permission check in a helper method for HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of AWS credentials stored in Jenkins in some ... Read more
Affected Products : cloudbees_aws_credentials- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2542
Netscape 6 and 8 allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.... Read more
Affected Products : navigator- Published: Jul. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3948
JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and application crash) via a long string at the end of a .wav file.... Read more
Affected Products : cowon_media_center-jetaudio- Published: Nov. 16, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4649
Multiple cross-site scripting (XSS) vulnerabilities in geccBBlite 0.1 allow remote attackers to inject arbitrary web script or HTML via the postatoda parameter to (1) rispondi.php and (2) scrivi.php, which is not properly handled in forum.php.... Read more
Affected Products : geccbblite- Published: Feb. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2376
Cross-site scripting (XSS) vulnerability in the Html::textarea function in application/libraries/Html.php in TangoCMS 2.x before 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the value parameter, related to the Contact module.... Read more
Affected Products : tangocms- Published: Jul. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4061
Multiple cross-site scripting (XSS) vulnerabilities in the Agreement module 6.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Nov. 24, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2316
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. N... Read more
Affected Products : tivoli_identity_manager- Published: Jul. 05, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-6123
Cross-site scripting (XSS) vulnerability in Microsoft Excel for Mac 2011 and Excel 2016 for Mac allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message that is mishandled by Outlook for Mac, aka "Microsoft Outlook for M... Read more
Affected Products : excel_for_mac- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-3901
Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to home/index.asp and other unspecified vectors.... Read more
Affected Products : e-courirer_cms- Published: Nov. 06, 2009
- Modified: Apr. 09, 2025