Latest CVE Feed
-
4.3
MEDIUMCVE-2013-1504
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2, 10.3.5, 10.3.6, and 12.1.1 allows remote attackers to affect integrity via unknown vectors related to WebLogic Console, a different vulnerability than CV... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1441
econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependent users to cause a denial of service (crash) via a crafted image file.... Read more
Affected Products : exactimage- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4969
Cross-site scripting (XSS) vulnerability in jQuery before 1.6.3, when using location.hash to select elements, allows remote attackers to inject arbitrary web script or HTML via a crafted tag.... Read more
Affected Products : jquery- Published: Mar. 08, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2845
Google Chrome before 15.0.874.102 does not properly handle history data, which allows user-assisted remote attackers to spoof the URL bar via unspecified vectors.... Read more
- Published: Oct. 25, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1171
Multiple cross-site scripting (XSS) vulnerabilities in the element-list implementation in Cisco Connected Grid Network Management System (CG-NMS) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCue14517... Read more
Affected Products : connected_grid_network_management_system- Published: Apr. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1055
The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks ... Read more
- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4006
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.... Read more
Affected Products : websphere_application_server- Published: Nov. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-26247
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing exter... Read more
- Published: Dec. 30, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20193
A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat from this vulnerability is to system availability.... Read more
Affected Products : tar- Published: Mar. 26, 2021
- Modified: May. 05, 2025
-
4.3
MEDIUMCVE-2013-3025
Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.5.x and 6.6.x before 6.6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : rational_focal_point- Published: Oct. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-26558
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and... Read more
Affected Products : linux_kernel fedora debian_linux ac_9461_firmware ac_9462_firmware ac_9560_firmware bluetooth_core_specification ax210_firmware ax201_firmware ax200_firmware +24 more products- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-3722
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."... Read more
- Published: May. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1445
The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive informati... Read more
Affected Products : pycrypto- Published: Oct. 26, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1456
Cross-site scripting (XSS) vulnerability in the login page in Open Web Analytics (OWA) before 1.5.6 allows remote attackers to inject arbitrary web script or HTML via the owa_user_id parameter to index.php.... Read more
Affected Products : open_web_analytics- Published: Mar. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-3041
The Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to obtain sensitive information from the client-server data stream via unspecified vectors associated with a "JSON hijackin... Read more
Affected Products : rational_clearquest- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1466
Multiple cross-site scripting (XSS) vulnerabilities in glFusion before 1.2.2.pl4 allow remote attackers to inject arbitrary web script or HTML via the (1) subject parameter to profiles.php; (2) address1, (3) address2, (4) calendar_type, (5) city, (6) stat... Read more
Affected Products : glfusion- Published: Feb. 05, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-1167
fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted (1) me... Read more
Affected Products : fetchmail- Published: May. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1524
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Attachments.... Read more
Affected Products : e-business_suite- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-34508
dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.... Read more
- Published: May. 05, 2024
- Modified: Jun. 10, 2025
-
4.3
MEDIUMCVE-2013-1014
Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.... Read more
- Published: May. 20, 2013
- Modified: Apr. 11, 2025