Latest CVE Feed
-
4.3
MEDIUMCVE-2007-5027
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/ddns in the web management panel for the WBR3404TX broadband router with firmware R1.94p0vTIG allow remote attackers to inject arbitrary web script or HTML via the (1) DD or (2) DU parameter.... Read more
Affected Products : wbr3404tx- Published: Sep. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2513
Novell GroupWise 7 before SP2 20070524, and GroupWise 6 before 6.5 post-SP6 20070522, allows remote attackers to obtain credentials via a man-in-the-middle attack.... Read more
Affected Products : groupwise- Published: Jun. 04, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2889
Cross-site scripting (XSS) vulnerability in Google Chrome before 22.0.1229.79 allows remote attackers to inject arbitrary web script or HTML via vectors involving frames, aka "Universal XSS (UXSS)."... Read more
- Published: Sep. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2134
The handle_connection_error function in ldap_helper.c in bind-dyndb-ldap before 1.1.0rc1 does not properly handle LDAP query errors, which allows remote attackers to cause a denial of service (infinite loop and named server hang) via a non-alphabet charac... Read more
Affected Products : bind-dyndb-ldap- Published: Feb. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-5119
JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain sensitive information (full path) via an invalid integer in the version parameter to the default URI under attach/Main/.... Read more
Affected Products : jspwiki- Published: Sep. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2126
RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.... Read more
- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-12432
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Non-member users who subscribed to issue notifications could access the title of confidential issues through the unsubscription page. It allows Information Disclosure.... Read more
Affected Products : gitlab- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-8453
Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to ... Read more
Affected Products : android linux_kernel flash_player mac_os_x iphone_os windows air air_sdk air_sdk_\&_compiler- Published: Dec. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-5058
Cross-site scripting (XSS) vulnerability in the Web administration interface in Barracuda Spam Firewall before firmware 3.5.10.016 allows remote attackers to inject arbitrary web script or HTML via the username field in a login attempt, which is not prope... Read more
Affected Products : barracuda_spam_firewall- Published: Sep. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5295
Multiple cross-site scripting (XSS) vulnerabilities in index.php in (a) Wikepage Opus 13 2007.2 and (b) TipiWiki 2 allow remote attackers to inject arbitrary web script or HTML via the (1) PageContent and (2) PageName parameters.... Read more
Affected Products : opus- Published: Oct. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5297
Cross-site scripting (XSS) vulnerability in index.php in Minki 1.30 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : minki- Published: Oct. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-12383
Tor Browser before 8.0.1 has an information exposure vulnerability. It allows remote attackers to detect the browser's UI locale by measuring a button width, even if the user has a "Don't send my language" setting.... Read more
Affected Products : tor_browser- Published: May. 28, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-8006
Cross-site scripting (XSS) vulnerability in the PageTriage toolbar in the PageTriage extension for MediWiki allows remote attackers to inject arbitrary web script or HTML via the page title.... Read more
Affected Products : pagetriage- Published: Nov. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-2400
Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scri... Read more
- Published: Jun. 25, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-12431
An issue was discovered in GitLab Community and Enterprise Edition 8.13 through 11.11. Restricted users could access the metadata of private milestones through the Search API. It has Improper Access Control.... Read more
Affected Products : gitlab- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10322
A missing permission check in Jenkins Artifactory Plugin 3.2.2 and earlier in ArtifactoryBuilder.DescriptorImpl#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtain... Read more
Affected Products : artifactory- Published: May. 31, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2391
Cross-site scripting (XSS) vulnerability in Apple Safari Beta 3.0.1 for Windows allows remote attackers to inject arbitrary web script or HTML via a web page that includes a windows.setTimeout function that is activated after the user has moved from the c... Read more
Affected Products : safari- Published: Jun. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2112
Cross-site scripting (XSS) vulnerability in the Exception Handler in TYPO3 4.4.x before 4.4.15, 4.5.x before 4.5.15, 4.6.x before 4.6.8, and 4.7 allows remote attackers to inject arbitrary web script or HTML via exception messages.... Read more
Affected Products : typo3- Published: Aug. 27, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-5621
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 and 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality via vectors related to... Read more
Affected Products : flexcube_universal_banking- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-5078
Multiple cross-site scripting (XSS) vulnerabilities in eGov Manager allow remote attackers to inject arbitrary web script or HTML via unspecified "user-supplied input" to (1) center.exe or (2) Index.exe.... Read more
Affected Products : manger- Published: Oct. 05, 2007
- Modified: Apr. 09, 2025