Latest CVE Feed
-
4.3
MEDIUMCVE-2014-2963
Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE allow remote attackers to inject arbitrary web script or HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_mid... Read more
Affected Products : liferay_portal- Published: Jul. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-100028
Cross-site scripting (XSS) vulnerability in /signup in WEBCrafted allows remote attackers to inject arbitrary web script or HTML via the username.... Read more
Affected Products : webcrafted- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-100036
Cross-site scripting (XSS) vulnerability in FlatPress 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the content parameter to the default URI.... Read more
Affected Products : flatpress- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3797
Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : vcenter_server_appliance- Published: Dec. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2326
Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 27, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3452
Filters\LAV\avfilter-lav-4.dll in K-lite Codec 10.4.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .jpg file.... Read more
- Published: May. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5935
The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 does not properly restrict the set of network interfaces that can receive API calls, which makes it easier for remote attackers to obtain access by se... Read more
Affected Products : open-xchange_appsuite- Published: Sep. 25, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-100023
Multiple cross-site scripting (XSS) vulnerabilities in question.php in the mTouch Quiz before 3.0.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the quiz parameter to wp-admin/edit.php.... Read more
Affected Products : mtouch_quiz- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-0564
Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.10b1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) editing templates and (2) the list's "info attribute" in the web administra... Read more
Affected Products : mailman- Published: Feb. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-0855
Multiple cross-site scripting (XSS) vulnerabilities in IBM Connections Portlets 4.x before 4.5.1 FP1 for IBM WebSphere Portal 7.0.0.2 and 8.0.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 14, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3808
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) role parameter to roles.lsp, (2) name parameter to user.lsp, (3) path parameter to wizard/setuser.... Read more
- Published: May. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3004
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.... Read more
- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0852
IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sen... Read more
- Published: Aug. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-0988
The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infinite loop) by unserializing certain integer expressions, which only cause 32-... Read more
- Published: Feb. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-2975
Cross-site scripting (XSS) vulnerability in php/user_account.php in Silver Peak VX before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.... Read more
Affected Products : vx- Published: Jul. 28, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5510
The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.5), whe... Read more
- Published: Oct. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2023
Cross-site scripting (XSS) vulnerability in functions/mime.php in SquirrelMail before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via a crafted STYLE element in an e-mail message.... Read more
- Published: Jul. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0390
Unspecified vulnerability in Oracle Solaris 10 allows remote attackers to affect integrity via unknown vectors related to Java Web Console.... Read more
- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0082
The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted cer... Read more
Affected Products : firefox- Published: Jun. 06, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-6179
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.0.x before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : websphere_service_registry_and_repository- Published: Dec. 24, 2014
- Modified: Apr. 12, 2025