Latest CVE Feed
-
4.3
MEDIUMCVE-2012-4972
Multiple cross-site scripting (XSS) vulnerabilities in Layton Helpbox 4.4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sys_solution_id, (2) sys_requesttype_id, (3) sys_problem_desc, (4) sys_solution_desc, (5) sys_problemsumm... Read more
Affected Products : helpbox- Published: Dec. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5913
Cross-site scripting (XSS) vulnerability in wp-integrator.php in the WordPress Integrator module 1.32 for WordPress allows remote attackers to inject arbitrary web script or HTML via the redirect_to parameter to wp-login.php.... Read more
- Published: Nov. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4901
Cross-site scripting (XSS) vulnerability in Template CMS 2.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the themes_editor parameter in an add_template action to admin/index.php.... Read more
Affected Products : template_cms- Published: May. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5470
libpng_plugin in VideoLAN VLC media player 2.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted PNG file.... Read more
Affected Products : vlc_media_player- Published: Oct. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5455
Cross-site scripting (XSS) vulnerability in the language search component in Joomla! before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "typographical error."... Read more
Affected Products : joomla\!- Published: Oct. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2382
Microsoft Internet Explorer 8 and earlier, and Internet Explorer 9 beta, does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attri... Read more
- Published: Jun. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4728
The (1) QProGetNotebookWindowHandle and (2) Ordinal132 functions in QPW160.dll in Corel Quattro Pro X6 Standard Edition 16.0.0.388 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted QPW file... Read more
Affected Products : quattro_pro_x6- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-5542
Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect integrity via vectors related to Libraries.... Read more
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4651
Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets from the Scan Safe Tower, aka Bug ID CSCub85451.... Read more
Affected Products : ios- Published: Apr. 23, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5187
The Weathernews Touch application 2.3.2 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.... Read more
Affected Products : weathernews_touch- Published: Feb. 06, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4928
Cross-site scripting (XSS) vulnerability in ow_updates/index.php in Oxwall 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the plugin parameter.... Read more
Affected Products : oxwall- Published: Sep. 15, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5855
The SHAddToRecentDocs function in VideoLAN VLC media player 2.0.4 and earlier might allow user-assisted attackers to cause a denial of service (crash) via a crafted file name that triggers an incorrect string-length calculation when the file is added to V... Read more
Affected Products : vlc_media_player- Published: Jul. 10, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5491
z3c.form, as used in Plone before 4.2.3 and 4.3 before beta 1, allows remote attackers to obtain the default form field values by leveraging knowledge of the form location and the element id.... Read more
Affected Products : plone- Published: Sep. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5346
Cross-site scripting (XSS) vulnerability in wp-live.php in the WP Live.php module 1.2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. NOTE: some of these details are obtained from third party informatio... Read more
- Published: Oct. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5093
Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect integrity via unknown vectors related to Global Spec Management.... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-22256
VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather information about organization names based on the behavior of the instance.... Read more
Affected Products : cloud_director- Published: Mar. 07, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5943
Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.... Read more
Affected Products : lotus_inotes- Published: Mar. 26, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5456
The Zoner AntiVirus Free application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrar... Read more
Affected Products : zoner_antivirus_free- Published: Oct. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5384
Multiple cross-site scripting (XSS) vulnerabilities in Craig Knudsen WebCalendar allow remote attackers to inject arbitrary web script or HTML via the (1) $name or (2) $description variables in edit_entry_handler.php, or (3) $url, (4) $tempfullname, or (5... Read more
Affected Products : webcalendar- Published: Oct. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6043
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.... Read more
- Published: Nov. 26, 2012
- Modified: Apr. 11, 2025