Latest CVE Feed
-
4.3
MEDIUMCVE-2007-6687
Multiple cross-site scripting (XSS) vulnerabilities in Menalto Gallery before 2.2.4 allow remote attackers to inject arbitrary web script or HTML via crafted filenames to the (1) Core or (2) add-item modules; or via (3) HTTP PROPPATCH in the WebDAV module... Read more
Affected Products : gallery- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6474
Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web script or HTML via the newdir parameter to index_3x.php, and unspecified other vectors.... Read more
Affected Products : gf_3xplorer- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5624
Cross-site scripting (XSS) vulnerability in Nagios 2.x before 2.10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts.... Read more
Affected Products : nagios- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0330
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).... Read more
Affected Products : gallery- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-5005
An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all versions starting from 17.3 before 17.3.5, all versions starting from 17.4 before 17.4.2 It was possible for guest users to disclose proje... Read more
Affected Products : gitlab- Published: Oct. 11, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2008-0037
X11 in Apple Mac OS X 10.5 through 10.5.1 does not properly handle when the "Allow connections from network client" preference is disabled, which allows remote attackers to bypass intended access restrictions and connect to the X server.... Read more
Affected Products : mac_os_x- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-4638
Integer overflow in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.... Read more
Affected Products : ffmpeg- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-7424
IBM InfoSphere Master Data Management (MDM) - Collaborative Edition 9.1, 10.1, 11.0, 11.3, 11.4, and 11.5 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information by leveraging Catalogs access. IBM X-Force I... Read more
Affected Products : infosphere_master_data_management- Published: Mar. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-6085
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VigileCMS 1.4 allow remote attackers to inject arbitrary web script or HTML via the message field in the (1) vedipm or (2) live_chat module.... Read more
Affected Products : vigilecms- Published: Nov. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4542
Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the (1) processLine function in maptemplate.c and the (2) writeError function in... Read more
Affected Products : mapserver- Published: Aug. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6452
Unspecified vulnerability in the benchmark reporting system in Google Web Toolkit (GWT) before 1.4.61 has unknown impact and attack vectors, possibly related to cross-site scripting (XSS).... Read more
Affected Products : web_toolkit- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6455
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Mambo 4.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Itemid parameter in a com_frontpage option and the (2) option parameter.... Read more
Affected Products : mambo- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-6389
An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a guest user was able to access commit information via the release Atom endpoint, contrary to permi... Read more
Affected Products : gitlab- Published: Sep. 12, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-52544
Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.... Read more
- Published: Apr. 08, 2024
- Modified: Mar. 13, 2025
-
4.3
MEDIUMCVE-2024-7057
An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from 17.2 prior to 17.2.1 where job artifacts can be inappropriately exposed to users lacki... Read more
Affected Products : gitlab- Published: Jul. 25, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-2720
Cross-site scripting (XSS) vulnerability in Menalto Gallery before 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) host and (2) path components of a URL.... Read more
Affected Products : gallery- Published: Jun. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0418
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI ... Read more
- Published: Feb. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0455
Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to... Read more
- Published: Jan. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-0741
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.... Read more
Affected Products : yabb- Published: Mar. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2014-6054
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) PalmVNCSe... Read more
- Published: Oct. 06, 2014
- Modified: Apr. 12, 2025