Latest CVE Feed
-
4.3
MEDIUMCVE-2013-0276
ActiveRecord in Ruby on Rails before 2.3.17, 3.1.x before 3.1.11, and 3.2.x before 3.2.12 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request.... Read more
- Published: Feb. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-26558
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and... Read more
Affected Products : linux_kernel fedora debian_linux ac_9461_firmware ac_9462_firmware ac_9560_firmware bluetooth_core_specification ax210_firmware ax201_firmware ax200_firmware +24 more products- Published: May. 24, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-0176
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" pac... Read more
Affected Products : libssh- Published: Feb. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0125
Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File parameter.... Read more
Affected Products : c2_webresource- Published: Apr. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3531
Cross-site scripting (XSS) vulnerability in the Install Tool in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : typo3- Published: Sep. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-9670
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file t... Read more
Affected Products : ubuntu_linux fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_eus opensuse solaris enterprise_linux_hpc_node +2 more products- Published: Feb. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1289
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka... Read more
- Published: Apr. 09, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6153
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-t... Read more
- Published: Sep. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-3437
The Magick_png_malloc function in coders/png.c in ImageMagick 6.7.8 and earlier does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers inc... Read more
Affected Products : imagemagick- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-17185
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a out-of-bounds read vulnerability. Due to ... Read more
Affected Products : dp300_firmware te60_firmware rp200_firmware te30_firmware te40_firmware te50_firmware te30 te40 te50 te60 +2 more products- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-2361
Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : system_management_homepage- Published: Jul. 22, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0342
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.... Read more
Affected Products : pyrad- Published: Dec. 09, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5093
Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 5.2.2 and 6.1.0.0 allows remote attackers to affect integrity via unknown vectors related to Global Spec Management.... Read more
Affected Products : supply_chain_products_suite- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2231
Unspecified vulnerability in the XML Developer Kit component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1, Oracle Fusion Middleware 10.1.3.5, allows remote attackers to affect availability via unknown vectors.... Read more
- Published: Jul. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2285
Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.... Read more
Affected Products : libtiff- Published: Jul. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-3041
The Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to obtain sensitive information from the client-server data stream via unspecified vectors associated with a "JSON hijackin... Read more
Affected Products : rational_clearquest- Published: Oct. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-2678
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable vulne... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1037
An information disclosure vulnerability exists when Visual Studio improperly discloses limited contents of uninitialized memory while compiling program database (PDB) files, aka "Microsoft Visual Studio Information Disclosure Vulnerability." This affects ... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-34508
dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.... Read more
- Published: May. 05, 2024
- Modified: Jun. 10, 2025
-
4.3
MEDIUMCVE-2010-3170
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 recognize a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-mid... Read more
- Published: Oct. 21, 2010
- Modified: Apr. 11, 2025