Latest CVE Feed
-
4.3
MEDIUMCVE-2010-0440
Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or ... Read more
- Published: Feb. 03, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0770
Cross-site scripting (XSS) vulnerability in Windows Event Log SmartConnector in HP ArcSight Connector Appliance before 6.1 allows remote attackers to inject arbitrary web script or HTML via the Windows XP variable in a file.... Read more
- Published: Jul. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0050
Cross-site scripting (XSS) vulnerability in the nonjs interface (interfaces/nonjs.pm) in CGI:IRC before 0.5.10 allows remote attackers to inject arbitrary web script or HTML via the R parameter.... Read more
Affected Products : cgi\- Published: Feb. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0734
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" atta... Read more
Affected Products : coldfusion- Published: Feb. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-15712
rConfig 3.9.5 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a crafted request to the ajaxGetFileByPath.php script containing hexadecimal encoded "dot dot" sequences (%2f..%2f) in the path paramet... Read more
Affected Products : rconfig- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0195
The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site. NOTE: this may overlap CVE-2011-1202.... Read more
Affected Products : iphone_os- Published: Apr. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0733
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header in an id=- query to a .cfm file.... Read more
Affected Products : coldfusion- Published: Feb. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-12399
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have.... Read more
- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0190
Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Appl... Read more
- Published: Mar. 23, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-0432
Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStore... Read more
Affected Products : ofbiz- Published: Apr. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-13437
The Book a Room plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.9. This is due to missing or incorrect nonce validation on the 'bookaroom_Settings' page. This makes it possible for unauthenticated a... Read more
Affected Products : book_a_room- Published: Feb. 12, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2011-0798
Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 10.1.2.3 and 11.1.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Midtier Infrastructure.... Read more
Affected Products : fusion_middleware- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-7488
Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.... Read more
Affected Products : authconfig- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2011-0163
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle unspecified "cached resources," which allows remote attackers to cause a denial of service (resource unavailability) via a crafted web site that conducts a cache-poi... Read more
- Published: Mar. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-0842
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated... Read more
- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-0746
Cross-site request forgery (CSRF) vulnerability in Forms/PortForwarding_Edit_1 on the ZyXEL O2 DSL Router Classic allows remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequences via the ... Read more
Affected Products : o2_dsl_router_classic- Published: Apr. 13, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0186
QuickTime in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG2000 image.... Read more
- Published: Mar. 23, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0741
Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image editor.... Read more
Affected Products : evolution- Published: Feb. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0773
Cross-site scripting (XSS) vulnerability in pivotx/modules/module_image.php in PivotX before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the image parameter.... Read more
Affected Products : pivotx- Published: Feb. 04, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0833
Unspecified vulnerability in the Siebel CRM Core component in Oracle Siebel CRM 7.8.2, 8.0.0, and 8.1.1 allows remote attackers to affect integrity, related to UIF Client.... Read more
Affected Products : siebel_crm- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025