Latest CVE Feed
-
4.3
MEDIUMCVE-2015-4467
The chmd_init_decomp function in chmd.c in libmspack before 0.5 does not properly validate the reset interval, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted CHM file.... Read more
- Published: Jun. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-4341
Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author permissions to execute arbitrary SQL commands via the filter paramet... Read more
Affected Products : symphony_cms- Published: Feb. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0323
Cross-site scripting (XSS) vulnerability in the Autocomplete plugin before 3.0 for SquirrelMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0309
Cross-site scripting (XSS) vulnerability in Cogent DataHub 7.1.2 and earlier, Cascade DataHub 6.4.20 and earlier, and OPC DataHub 6.4.20 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jan. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0799
Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.... Read more
Affected Products : moodle- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-38506
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3,... Read more
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-0283
Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.... Read more
Affected Products : dokuwiki- Published: Jul. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2611
Unspecified vulnerability in the printing functionality in Opera before 11.50 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted web page.... Read more
Affected Products : opera_browser- Published: Jul. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1977
The ASP.NET Chart controls in Microsoft .NET Framework 4, and Chart Control for Microsoft .NET Framework 3.5 SP1, do not properly verify functions in URIs, which allows remote attackers to read arbitrary files via special characters in a URI in an HTTP re... Read more
- Published: Aug. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4670
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) viewname parameter in a CalendarAjax action, (2) activity_mode parameter in a DetailView action, ... Read more
Affected Products : vtiger_crm- Published: Dec. 02, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-1462
An information disclosure vulnerability exists when Skype for Business is accessed via Microsoft Edge (EdgeHTML-based), aka 'Skype for Business via Microsoft Edge (EdgeHTML-based) Information Disclosure Vulnerability'.... Read more
- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-0007
The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attack... Read more
Affected Products : anti-cross_site_scripting_library- Published: Jan. 10, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0849
Integer overflow in the ff_j2k_dwt_init function in libavcodec/j2k_dwt.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted JPEG2000 image that triggers an incorrect check f... Read more
Affected Products : ffmpeg- Published: Aug. 27, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4561
Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin/index.php. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : phorum- Published: Nov. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0834
Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.... Read more
- Published: Feb. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0873
Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode paramete... Read more
Affected Products : dolphin- Published: Feb. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4750
Multiple cross-site scripting (XSS) vulnerabilities in SmarterTools SmarterStats 6.2.4100 allow remote attackers to inject arbitrary web script or HTML via crafted input to a PHP script, as demonstrated by Default.aspx and certain other files.... Read more
Affected Products : smarterstats- Published: Dec. 16, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0471
Cross-site request forgery (CSRF) vulnerability in privmsg.php in phpBB 2.0.22 allows remote attackers to delete private messages (PM) as arbitrary users via a deleteall action.... Read more
Affected Products : phpbb- Published: Jan. 29, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4872
Perl-Compatible Regular Expression (PCRE) library before 6.2 does not properly count the number of named capturing subpatterns, which allows context-dependent attackers to cause a denial of service (crash) via a regular expression with a large number of n... Read more
Affected Products : pcre- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-5301
Multiple cross-site scripting (XSS) vulnerabilities in PHPDug 2.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the story_url parameter to add_story.php, (2) the email parameter to editprofile.php, (3) the title parameter to adm/... Read more
Affected Products : phpdug- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025