Latest CVE Feed
-
4.3
MEDIUMCVE-2024-3844
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)... Read more
- Published: Apr. 17, 2024
- Modified: Dec. 19, 2024
-
4.3
MEDIUMCVE-2014-1441
Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL command with malformed data, as demonstrated by pressing the enter key twice.... Read more
Affected Products : core_ftp- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5149
The Push Notifications subsystem in Apple iOS before 7 provides the push-notification token to an app without user approval, which allows attackers to obtain sensitive information via an app that employs a crafted push-notification registration process.... Read more
Affected Products : iphone_os- Published: Sep. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5129
Multiple cross-site scripting (XSS) vulnerabilities in WebKit in Apple iOS before 7 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.... Read more
Affected Products : iphone_os- Published: Sep. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1472
Multiple cross-site scripting (XSS) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : vulnerability_manager- Published: Jan. 16, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1566
Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.... Read more
- Published: Sep. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5095
Cross-site scripting (XSS) vulnerability in the web-based interface in Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka ... Read more
- Published: Aug. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-5266
Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary w... Read more
- Published: Nov. 28, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5225
Multiple cross-site scripting (XSS) vulnerabilities in Xerox DocuShare 6 and earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) SearchResults/ and (2) Services/ in dsdn/dsweb/, and (3) the ... Read more
Affected Products : docushare- Published: Nov. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-5057
hxds.dll in Microsoft Office 2007 SP3 and 2010 SP1 and SP2 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted COM component on a web site that is visited with Internet Explo... Read more
Affected Products : office- Published: Dec. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1754
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to injec... Read more
- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5006
main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware 1.05.12, 1.06.18, and 1.06.28, allows remote attackers to discover the cleartext administrative password by reading the "... Read more
- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0156
DirectWrite in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly render Unicode characters, which allows remote attackers to cause a denial of service (application hang) via a (1) instant me... Read more
- Published: Mar. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0145
Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a UR... Read more
- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-3127
Vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite (subcomponent: Product Security). Supported versions that are affected are 7.3.5 and 12.2. Easily exploitable vulnerability allows unauthenticated attac... Read more
Affected Products : demantra_demand_management- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3414
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName ... Read more
- Published: Jul. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0085
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 7.5.2 and 10.1.3.5.1 allows remote attackers to affect integrity via unknown vectors related to Content Server.... Read more
Affected Products : fusion_middleware- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3413
The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.... Read more
Affected Products : kde_pim- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1808
Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability."... Read more
Affected Products : office- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-0010
Microsoft Internet Explorer 6 through 9 does not properly perform copy-and-paste operations, which allows user-assisted remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Copy and Paste Information Disclo... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_server_2003 windows_vista windows_xp- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025