Latest CVE Feed
-
4.3
MEDIUMCVE-2016-7577
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "FaceTime" component, which allows remote attackers to trigger memory corruption and obtain audio data from a call tha... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2011-4696
Directory traversal vulnerability in Eye-Fi Helper before 3.4.23 allows man-in-the-middle attackers to create arbitrary files via a .. (dot dot) in the filesignature in a GetPhotoStatus request.... Read more
Affected Products : eye-fi_helper- Published: Mar. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20420
IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281.... Read more
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20788
Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the ver... Read more
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-2313
Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.... Read more
- Published: Mar. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3089
Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as... Read more
Affected Products : firefox- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-20424
IBM Cloud Pak for Applications 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. X-Force ID: 196309.... Read more
Affected Products : cloud_pak_for_applications- Published: Jul. 13, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21185
Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension.... Read more
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-6749
Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file.... Read more
Affected Products : vorbis-tools- Published: Sep. 21, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7976
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-1492
The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which migh... Read more
Affected Products : network_security_services- Published: Mar. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20786
Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the vers... Read more
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2871
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this is... Read more
- Published: Jun. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-1221
Cross-zone scripting vulnerability in the RealPlayer ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5, RealPlayer SP 1.0 through 1.1.5, and RealPlayer Enterprise 2.0 through 2.1.5 allows remote attackers to inject arb... Read more
- Published: Oct. 04, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-3439
Cross-site scripting (XSS) vulnerability in the Ephox (formerly Moxiecode) plupload.flash.swf shim 2.1.2 in Plupload, as used in WordPress 3.9.x, 4.0.x, and 4.1.x before 4.1.2 and other products, allows remote attackers to execute same-origin JavaScript f... Read more
- Published: Aug. 05, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20306
A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The highest threat from this vulnerabi... Read more
- Published: Jun. 01, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2808
Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb 4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web script or HTML via the database parameter.... Read more
- Published: May. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-2597
The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x through 1.4.7, and 1.6.0 allows remote attackers to cause a denial of service (infinite loop) via malformed packets.... Read more
Affected Products : wireshark- Published: Jul. 07, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1337
Opera before 11.50 allows remote attackers to cause a denial of service (disk consumption) via invalid URLs that trigger creation of error pages.... Read more
Affected Products : opera_browser- Published: Jul. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-20777
Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.... Read more
Affected Products : gu- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024