Latest CVE Feed
-
4.3
MEDIUMCVE-2019-15684
Kaspersky Protection extension for web browser Google Chrome prior to 30.112.62.0 was vulnerable to unauthorized access to its features remotely that could lead to removing other installed extensions.... Read more
- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-6673
Cross-site scripting (XSS) vulnerability in Makale Scripti allows remote attackers to inject arbitrary web script or HTML via the ara parameter to the default URI under Ara/ in a search action.... Read more
Affected Products : makale_scripti- Published: Jan. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4903
Cross-site scripting (XSS) vulnerability in the leave comment (feedback) feature in Typo 5.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) comment[author] (Name) and (2) comment[url] (Website) parameters.... Read more
Affected Products : typo- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5266
Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to cause a denial of service (crash) via a crafted PNG image that prevents a name f... Read more
Affected Products : libpng- Published: Oct. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-0190
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1619
Cross-site scripting (XSS) vulnerability in the fix_non_standard_entities function in the KSES HTML text cleaning library (weblib.php), as used in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8, allows remote attackers to inject arbitrary web script or... Read more
Affected Products : moodle- Published: Apr. 29, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-3964
An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public p... Read more
Affected Products : gitlab- Published: Dec. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2010-1640
Off-by-one error in the parseicon function in libclamav/pe_icons.c in ClamAV 0.96 allows remote attackers to cause a denial of service (crash) via a crafted PE icon that triggers an out-of-bounds read, related to improper rounding during scaling.... Read more
Affected Products : clamav- Published: May. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6617
Cross-site scripting (XSS) vulnerability in 500page.jsp in JIRA Enterprise Edition before 3.12.1 allows remote attackers to inject arbitrary web script or HTML, which is not properly handled when generating error messages, as demonstrated by input origina... Read more
- Published: Jan. 03, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6545
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) the subject parameter to modules/news/submit.php; (2) the PATH_INFO to modules/news/index.php, possibly relate... Read more
Affected Products : runcms- Published: Dec. 28, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6571
Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.... Read more
- Published: Dec. 28, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1724
Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php,... Read more
Affected Products : zikula_application_framework- Published: May. 06, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6677
Cross-site scripting (XSS) vulnerability in Peter's Random Anti-Spam Image 0.2.4 and earlier plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the comment field in the comment form.... Read more
Affected Products : random_anti-spam_image- Published: Jan. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1778
Cross-site scripting (XSS) vulnerability in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via an RSS feed.... Read more
- Published: Jul. 30, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6599
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAl... Read more
- Published: Jan. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3622
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message that reaches a mailing-list archive, aka "persistent JavaScript injection."... Read more
- Published: Sep. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-6558
TotalPlayer 3.0 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .m3u file. NOTE: this might be a duplicate of CVE-2006-6288.... Read more
Affected Products : totalplayer- Published: Dec. 28, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5363
The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to ... Read more
- Published: Dec. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1899
Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repe... Read more
- Published: Sep. 15, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-0330
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).... Read more
Affected Products : gallery- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025