Latest CVE Feed
-
4.3
MEDIUMCVE-2024-47159
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project... Read more
Affected Products : youtrack- Published: Sep. 19, 2024
- Modified: Sep. 24, 2024
-
4.3
MEDIUMCVE-2016-4379
The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle atta... Read more
- Published: Sep. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2002-1276
An incomplete fix for a cross-site scripting (XSS) vulnerability in SquirrelMail 1.2.8 calls the strip_tags function on the PHP_SELF value but does not save the result back to that variable, leaving it open to cross-site scripting attacks.... Read more
- Published: Nov. 29, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2016-4620
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.... Read more
Affected Products : iphone_os- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-2091
The dwarf_read_cie_fde_prefix function in dwarf_frame2.c in libdwarf 20151114 allows attackers to cause a denial of service (out-of-bounds read) via a crafted ELF object file.... Read more
Affected Products : libdwarf- Published: Feb. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-39734
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site... Read more
Affected Products : datacap- Published: Jul. 14, 2024
- Modified: Mar. 25, 2025
-
4.3
MEDIUMCVE-2016-1616
The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.... Read more
Affected Products : chrome- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-44141
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be ... Read more
- Published: Feb. 21, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2022-21673
Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward ... Read more
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-11050
An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016).... Read more
Affected Products : s5_firmware note3_firmware s4_firmware note2_firmware s3_firmware s5 note3 s4 note2 s3- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-2158
lib/ajax/getnavbranch.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3, when the forcelogin feature is enabled, allows remote attackers to obtain sensitive category-detail information from ... Read more
Affected Products : moodle- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-1637
Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.... Read more
- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-3450
Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote attackers to affect confidentiality via vectors related to Services, a different vulnerability than CVE-2... Read more
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1183
NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitr... Read more
Affected Products : terasoluna_server_framework_for_java_web- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-3550
Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality via vectors related to Hotspot.... Read more
- Published: Jul. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1658
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.... Read more
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-3649
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated administrators to enumerate administrator accounts via modified GET requests.... Read more
Affected Products : endpoint_protection_manager- Published: Jun. 30, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-4909
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted application.... Read more
- Published: Sep. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-1012
Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the article parameter.... Read more
Affected Products : deskpro- Published: Feb. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-7417
Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING. NOTE: this can be used to bypass the cross-site request forgery... Read more
Affected Products : ipcop- Published: Jan. 02, 2015
- Modified: Apr. 12, 2025