Latest CVE Feed
-
4.3
MEDIUMCVE-2011-2175
Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a malformed Visual Networks file that triggers a heap-ba... Read more
Affected Products : wireshark- Published: Jun. 06, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-3725
MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app.... Read more
Affected Products : iphone_os- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-31426
Cross-Site Request Forgery (CSRF) vulnerability in Data443 Inline Related Posts.This issue affects Inline Related Posts: from n/a through 3.3.1. ... Read more
Affected Products : inline_related_posts- Published: Apr. 15, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-34995
svnWebUI v1.8.3 was discovered to contain an arbitrary file deletion vulnerability via the dirTemps parameter under com.cym.controller.UserController#importOver. This vulnerability allows attackers to delete arbitrary files via a crafted POST request.... Read more
Affected Products :- Published: May. 24, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-1384
Cross-site scripting (XSS) vulnerability in the Banner Effect Header plugin before 1.2.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the banner_effect_divid parameter in the BannerEffectOptions page to wp-admin/options... Read more
Affected Products : banner_effect_header- Published: Feb. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3720
The kernel in Apple OS X before 10.10.4 does not properly manage memory in kernel-extension APIs, which allows attackers to obtain sensitive memory-layout information via a crafted app.... Read more
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2741
Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass... Read more
- Published: Jul. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2745
Multiple cross-site scripting (XSS) vulnerabilities in the Search app in Gaia in Mozilla Firefox OS before 2.2 allow remote attackers to inject arbitrary HTML via the (1) name or (2) title field in card content associated with a search link that is mishan... Read more
Affected Products : firefox_os- Published: Aug. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-6331
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated HPGL file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is ca... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-41734
Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availa... Read more
Affected Products : netweaver_application_server_abap- Published: Aug. 13, 2024
- Modified: Sep. 12, 2024
-
4.3
MEDIUMCVE-2015-1966
Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before FP17, 6.2.1 before FP9, and 6.2.2 before FP15, as used in Security Access Manager for Mobile and other products, allow remote attackers to inj... Read more
Affected Products : tivoli_federated_identity_manager- Published: Jul. 04, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-2107
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.181.22 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.22 and earlier on Android, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, rel... Read more
- Published: Jun. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-3786
The Bluetooth subsystem in Apple OS X before 10.10.5 does not properly restrict Notification Center Service access, which allows attackers to read Notification Center notifications of certain paired devices via a crafted app.... Read more
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1908
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF16, and 8.5.0 through CF05, as used in Web Content Manager and other products, allo... Read more
Affected Products : websphere_portal- Published: Apr. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9738
Multiple cross-site scripting (XSS) vulnerabilities in the Tournament module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) account username, a (2) node title, ... Read more
Affected Products : tournament- Published: Jul. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1995
Multiple cross-site scripting (XSS) vulnerabilities in IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1494
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an mfbfw[*] parameter in an update action to wp-admin/admin-post.php, as demons... Read more
- Published: Feb. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1444
Multiple cross-site scripting (XSS) vulnerabilities in the web administration frontend in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allow remote attackers to inject arbitrary web script or HTML via the (1) conntrack.cgi, (2) index... Read more
Affected Products : fli4l- Published: Feb. 06, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1967
MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used.... Read more
Affected Products : websphere_mq- Published: Jul. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1852
The s3_token middleware in OpenStack keystonemiddleware before 1.6.0 and python-keystoneclient before 1.4.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allo... Read more
- Published: Apr. 17, 2015
- Modified: Apr. 12, 2025