Latest CVE Feed
-
4.3
MEDIUMCVE-2012-2211
Cross-site scripting (XSS) vulnerability in phpgwapi/inc/common_functions_inc.php in eGroupware before 1.8.004.20120405 allows remote attackers to inject arbitrary web script or HTML via the menuaction parameter to etemplate/process_exec.php. NOTE: some ... Read more
Affected Products : egroupware- Published: Nov. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3238
Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.... Read more
- Published: Jul. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-28166
SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful exploitation, the attacker can cause a low impact on the Integrit... Read more
- Published: Aug. 13, 2024
- Modified: Dec. 10, 2024
-
4.3
MEDIUMCVE-2024-21233
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 31, 2024
-
4.3
MEDIUMCVE-2019-8698
A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in iOS 12.4, tvOS 12.4. A malicious application may be able to restrict access to websites.... Read more
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-2645
The Yahoo! Japan Yahoo! Browser application 1.2.0 and earlier for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.... Read more
- Published: Jul. 16, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2674
Multiple integer overflows in the (1) chk_malloc, (2) leak_malloc, and (3) leak_memalign functions in libc/bionic/malloc_debug_leak.c in Bionic (libc) for Android, when libc.debug.malloc is set, make it easier for context-dependent attackers to perform me... Read more
Affected Products : bionic- Published: Jul. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0587
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0586, CVE-2012-0588, and CVE-2012-0589.... Read more
Affected Products : iphone_os- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3161
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1.1 allows remote attackers to affect integrity via unknown vectors related to Web Client (CS).... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-4901
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-2599
Google Chrome 11 does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.... Read more
Affected Products : chrome- Published: Jun. 30, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4016
The ATOK application before 1.0.4 for Android allows remote attackers to read the learning information file, and obtain sensitive input-string information, via a crafted application.... Read more
- Published: Sep. 28, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0560
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50, 8.51, and 8.52 allows remote attackers to affect integrity via unknown vectors related to Portal.... Read more
Affected Products : peoplesoft_products- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0040
Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.... Read more
Affected Products : simplesamlphp- Published: Jan. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-4018
Cross-site scripting (XSS) vulnerability in Final Beta Laboratory MyWebSearch before 1.23 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.... Read more
Affected Products : mywebsearch- Published: Oct. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0047
Cross-site scripting (XSS) vulnerability in Apache Wicket 1.4.x before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the wicket:pageMapName parameter.... Read more
Affected Products : wicket- Published: Mar. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0589
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0586, CVE-2012-0587, and CVE-2012-0588.... Read more
Affected Products : iphone_os- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3232
Cross-site scripting (XSS) vulnerability in search.php in web@all 2.0, as downloaded before May 30, 2012, allows remote attackers to inject arbitrary web script or HTML via the _text[title] parameter.... Read more
Affected Products : web\@all- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-17482
An issue has been found in PowerDNS Authoritative Server before 4.3.1 where an authorized user with the ability to insert crafted records into a zone might be able to leak the content of uninitialized memory.... Read more
- Published: Oct. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-3333
CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks v... Read more
- Published: May. 26, 2014
- Modified: Apr. 12, 2025