Latest CVE Feed
-
4.3
MEDIUMCVE-2012-3986
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict calls to DOMWindowUtils (aka nsDOMWindowUtils) methods, which allows remote attack... Read more
Affected Products : firefox firefox_esr thunderbird ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_eus linux_enterprise_server +4 more products- Published: Oct. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3546
org/apache/catalina/realm/RealmBase.java in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.30, when FORM authentication is used, allows remote attackers to bypass security-constraint checks by leveraging a previous setUserPrincipal call and then placi... Read more
Affected Products : tomcat- Published: Dec. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-4047
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those resources were requested when parsing certain parts of the... Read more
Affected Products : open-xchange_appsuite- Published: Dec. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-6024
IBM Jazz technology based products might divulge information that might be useful in helping attackers through error messages. IBM X-Force ID: 116868.... Read more
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2009-3265
Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as "scripted content." NOTE: the ven... Read more
Affected Products : opera_browser- Published: Sep. 18, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-6060
An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547.... Read more
- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2012-2667
Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."... Read more
Affected Products : symfony- Published: Jun. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-2313
Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.... Read more
- Published: Mar. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-2520
Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, ... Read more
- Published: Oct. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2417
PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key... Read more
Affected Products : pycrypto- Published: Jun. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUM- Published: Mar. 22, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-6122
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users.... Read more
Affected Products : kenexa_lms_on_cloud- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-7570
Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.... Read more
Affected Products : drupal- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-6094
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2025-8579
Inappropriate implementation in Picture In Picture in Google Chrome prior to 139.0.7258.66 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2016-7577
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "FaceTime" component, which allows remote attackers to trigger memory corruption and obtain audio data from a call tha... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2025-8583
Inappropriate implementation in Permissions in Google Chrome prior to 139.0.7258.66 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Aug. 07, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Misconfiguration
-
4.3
MEDIUMCVE-2021-20148
ManageEngine ADSelfService Plus below build 6116 stores the password policy file for each domain under the html/ web root with a predictable filename based on the domain name. When ADSSP is configured with multiple Windows domains, a user from one domain ... Read more
Affected Products : manageengine_adselfservice_plus- Published: Jan. 03, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1871
Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page.... Read more
- Published: Jul. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-1637
Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.... Read more
- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024