Latest CVE Feed
-
4.3
MEDIUMCVE-2007-6244
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allow remote attackers to inject arbitrary web script or HTML via (1) a SWF file that uses the asfunction: protocol or (2) the navigateToUR... Read more
Affected Products : flash_player- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-0799
The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 resp... Read more
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-34802
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.... Read more
Affected Products : rocketchat_notifier- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6359
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated PLT file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2544
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, aka "Exchange Spoofing Vu... Read more
Affected Products : exchange_server- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-4544
IBM Jazz Foundation Products could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 183189.... Read more
Affected Products : rational_doors_next_generation rational_collaborative_lifecycle_management rational_engineering_lifecycle_manager rational_quality_manager rational_rhapsody_design_manager rational_team_concert rhapsody_model_manager collaborative_lifecycle_management doors_next engineering_insights +5 more products- Published: Jan. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-3284
Unspecified vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to obtain sensitive information via unknown vectors.... Read more
Affected Products : system_management_homepage- Published: Sep. 24, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-0810
Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript ... Read more
- Published: Apr. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2556
The InfoPath Forms Services component in Microsoft SharePoint Server 2007 SP3 and 2010 SP2 misparses DTDs, which allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity re... Read more
Affected Products : sharepoint_server- Published: Oct. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0825
Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory all... Read more
- Published: Feb. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2489
Microsoft Internet Explorer 11 allows remote attackers to gain privileges via a crafted web site, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Elevation of Privilege Vulnerability."... Read more
Affected Products : internet_explorer- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-2915
Google Chrome before 30.0.1599.66 preserves pending NavigationEntry objects in certain invalid circumstances, which allows remote attackers to spoof the address bar via a URL with a malformed scheme, as demonstrated by a nonexistent:12121 URL.... Read more
Affected Products : chrome- Published: Oct. 02, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-32333
TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.... Read more
- Published: Apr. 18, 2024
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-6343
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated EPS file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-2475
Cross-site scripting (XSS) vulnerability in uddi/search/frames.aspx in the UDDI Services component in Microsoft Windows Server 2008 SP2 and BizTalk Server 2010, 2013 Gold, and 2013 R2 allows remote attackers to inject arbitrary web script or HTML via the ... Read more
- Published: Aug. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2472
Remote Desktop Session Host (RDSH) in Remote Desktop Protocol (RDP) through 8.1 in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does no... Read more
- Published: Aug. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4847
Unspecified vulnerability in the Oracle Configurator component in Oracle Supply Chain Products Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via vectors related to OCI.... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0840
The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (.dsc).... Read more
- Published: Apr. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-6432
Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.... Read more
- Published: Apr. 13, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6438
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.... Read more
- Published: Apr. 13, 2020
- Modified: Nov. 21, 2024