Latest CVE Feed
-
4.3
MEDIUMCVE-2008-1241
GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remote attackers to spoof form elements and redirect user inputs via a borderless XUL pop-up window from a background tab.... Read more
- Published: Mar. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-1065
Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary files via the ExportSettings method.... Read more
Affected Products : applicationserver- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-0881
CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.... Read more
Affected Products : squid- Published: Feb. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-2402
Cross-site scripting (XSS) vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : network_automation- Published: Aug. 01, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-0443
index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.... Read more
Affected Products : cubecart- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-1049
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers to inject arbitrary web script or HTML via the (1) domainName parameter to jsp/AddDC.jsp or (2) operation parameter to DomainConfig.do... Read more
- Published: Feb. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1080
Cross-site scripting (XSS) vulnerability in the Euro Calculator (skt_eurocalc) extension 0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1048
Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and possibly other editions, allows remote attackers to inject arbitrary web script or HTML via the filter parameter.... Read more
Affected Products : efront_community_\+\+- Published: Feb. 12, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1039
Multiple cross-site scripting (XSS) vulnerabilities in Dotclear before 2.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) login_data parameter to admin/auth.php; (2) nb parameter to admin/blogs.php; (3) type, (4) sortby, (5) o... Read more
Affected Products : dotclear- Published: Mar. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-52594
Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advis... Read more
Affected Products : gomatrixserverlib- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Server-Side Request Forgery
-
4.3
MEDIUMCVE-2012-1073
Cross-site scripting (XSS) vulnerability in the Category-System (toi_category) extension 0.6.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 14, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2383
Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attackers to read cookie files via vectors involving an IFRAME element with a SRC attribute containing an http: URL th... Read more
- Published: Jun. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3034
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls.... Read more
- Published: Sep. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1038
Cross-site scripting (XSS) vulnerability in the WebAAA login functionality (wba_login.html) in Juniper Networks Mobility System Software (MSS) 7.6.x before 7.6.3, 7.7.x before 7.7.1, 7.5.x before 7.5.3, and other unspecified versions before 7.4 and 7.3 al... Read more
Affected Products : networks_mobility_system_software- Published: Apr. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-4907
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-1158
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) 5.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via an unexpected URI scheme, as demonstrated by a jav... Read more
Affected Products : feedparser- Published: Apr. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-20497
A vulnerability in Cisco Expressway Edge (Expressway-E) could allow an authenticated, remote attacker to masquerade as another user on an affected system. This vulnerability is due to inadequate authorization checks for Mobile and Remote Access (MRA) u... Read more
- Published: Sep. 04, 2024
- Modified: Aug. 12, 2025
-
4.3
MEDIUMCVE-2012-1007
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 1.3.10 allow remote attackers to inject arbitrary web script or HTML via (1) the name parameter to struts-examples/upload/upload-submit.do, or the message parameter to (2) struts-cookboo... Read more
Affected Products : struts- Published: Feb. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1143
epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark before 1.4.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted .pcap file.... Read more
Affected Products : wireshark- Published: Mar. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2357
Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local applications to bypass the sandbox and execute arbitrary Javascript in arbitrary domains by (1) causing the MAX_TAB number of tabs to ... Read more
Affected Products : android- Published: Aug. 12, 2011
- Modified: Apr. 11, 2025