Latest CVE Feed
-
4.3
MEDIUMCVE-2013-4238
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitra... Read more
- Published: Aug. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-20193
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.... Read more
Affected Products : tar- Published: Mar. 26, 2021
- Modified: May. 05, 2025
-
4.3
MEDIUMCVE-2013-4006
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.... Read more
Affected Products : websphere_application_server- Published: Nov. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5118
Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail message.... Read more
Affected Products : good_for_enterprise- Published: Sep. 25, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1571
Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors ... Read more
- Published: Jun. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6040
Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : file_king_advanced_file_management- Published: Nov. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5711
Cross-site scripting (XSS) vulnerability in admin/walkthrough/walkthrough.php in the Design Approval System plugin before 3.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.... Read more
Affected Products : design_approval_system_plugin- Published: Sep. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5749
Cross-site scripting (XSS) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to inject arbitrary web script or HTML via the new_project parameter.... Read more
Affected Products : simplerisk- Published: May. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5670
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) via vectors related to BDF fonts and an ENCODING field with a negative value.... Read more
Affected Products : freetype- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6092
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or ... Read more
Affected Products : activemq- Published: Apr. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4939
Cross-site scripting (XSS) vulnerability in io.swf in the IO Utility component in Yahoo! YUI 3.0.0 through 3.9.1, as used in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.1, and other products, allows... Read more
- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5714
Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) me... Read more
Affected Products : wordpress videowhisper_live_streaming_integration live_streaming_integration_plugin- Published: Sep. 09, 2013
- Modified: Aug. 20, 2025
-
4.3
MEDIUMCVE-2013-4202
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expa... Read more
- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5773
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5.0 allows remote attackers to affect integrity via unknown vectors related to Servlet Runtime.... Read more
Affected Products : fusion_middleware- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5718
The dissect_nbap_T_dCH_ID function in epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not restrict the dch_id value, which allows remote attackers to cause a denial of service (application... Read more
Affected Products : wireshark- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5738
The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site... Read more
Affected Products : wordpress- Published: Sep. 12, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1996
Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.0 allows remote attackers to modify data via unknown vectors.... Read more
Affected Products : systems_insight_manager- Published: Mar. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2396
VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file.... Read more
Affected Products : vlc_media_player- Published: Apr. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4935
The dissect_per_length_determinant function in epan/dissectors/packet-per.c in the ASN.1 PER dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize a length field in certain abnormal situations, which allows remote attacker... Read more
Affected Products : wireshark- Published: Jul. 30, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6131
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.... Read more
Affected Products : roundup- Published: Apr. 11, 2014
- Modified: Apr. 12, 2025