Latest CVE Feed
-
4.3
MEDIUMCVE-2007-0562
Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .avi file, which triggers the crash when the user right clicks on the file.... Read more
Affected Products : windows_explorer- Published: Jan. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6200
Multiple cross-site scripting (XSS) vulnerabilities in Swiki 1.5 allow remote attackers to inject arbitrary web script or HTML via (1) the query string and (2) a new wiki entry.... Read more
Affected Products : swiki- Published: Feb. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-2434
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (U... Read more
- Published: Jul. 10, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-4872
Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solel... Read more
Affected Products : itechbids- Published: Nov. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2234
Cross-site scripting (XSS) vulnerability in sources/users.queries.php in TeamPass before 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the login parameter in an add_new_user action.... Read more
Affected Products : teampass- Published: Apr. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3328
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (... Read more
- Published: Feb. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2912
Multiple cross-site scripting (XSS) vulnerabilities in the LeagueManager plugin 3.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter in the show-league page or (2) season parameter in the team page to... Read more
- Published: May. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2918
Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the v parameter.... Read more
Affected Products : chevereto- Published: May. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-5056
Cross-site scripting (XSS) vulnerability in department_offline_context.php in ActiveCampaign TrioLive before 1.58.7 allows remote attackers to inject arbitrary web script or HTML via the department_id parameter to index.php.... Read more
Affected Products : triolive- Published: Nov. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-2026
IBM Financial Transaction Manager 3.2.1 for Digital Payments could allow an authenticated user to obtain a directory listing of internal product files. IBM X-Force ID: 155552.... Read more
Affected Products : financial_transaction_manager- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-10732
In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart em... Read more
- Published: Apr. 07, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-25750
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.... Read more
Affected Products : firefox- Published: Jun. 02, 2023
- Modified: Jan. 09, 2025
-
4.3
MEDIUMCVE-2018-18511
Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.... Read more
Affected Products : firefox- Published: Apr. 26, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-18585
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).... Read more
- Published: Oct. 23, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3393
The Clientless SSL VPN portal customization framework in Cisco ASA Software 8.2 before 8.2(5.51), 8.3 before 8.3(2.42), 8.4 before 8.4(7.23), 8.6 before 8.6(1.14), 9.0 before 9.0(4.24), 9.1 before 9.1(5.12), and 9.2 before 9.2(2.4) does not properly imple... Read more
Affected Products : adaptive_security_appliance_software- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2003-1527
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.... Read more
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1506
Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the DENIEDURL parameter.... Read more
Affected Products : dansguardian- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1534
Cross-site scripting (XSS) vulnerability in jgb.php3 in Justice Guestbook 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) aim, (4) yim, (5) location, and (6) comment variables.... Read more
Affected Products : guestbook- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1484
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) by creating a DHTML link that uses the AnchorClick "A" object with a blank href attribute.... Read more
Affected Products : ie- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2014-3438
Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : endpoint_protection_manager- Published: Nov. 07, 2014
- Modified: Apr. 12, 2025