Latest CVE Feed
-
4.3
MEDIUMCVE-2022-1495
Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a remote attacker to spoof the APK downloads dialog via a crafted HTML page.... Read more
- Published: Jul. 26, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2600
In jenkins before versions 2.44, 2.32.2 node monitor data could be viewed by low privilege users via the remote API. These included system configuration and runtime information of these nodes (SECURITY-343).... Read more
Affected Products : jenkins- Published: May. 15, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2606
Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have access) that wer... Read more
Affected Products : jenkins- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-8021
Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 11.4.0 before HF8 and 11.4.1 before ... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager big-ip_edge_gateway +3 more products- Published: Apr. 12, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-4485
Google Chrome before 8.0.552.215 does not properly restrict the generation of file dialogs, which allows remote attackers to cause a denial of service (reduced usability and possible application crash) via a crafted web site.... Read more
Affected Products : chrome- Published: Dec. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-20788
Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the ver... Read more
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-5251
Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type of a data: URL.... Read more
Affected Products : firefox- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-2988
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated att... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2871
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this is... Read more
- Published: Jun. 01, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-0920
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respectiv... Read more
Affected Products : gitlab- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-2117
Directory traversal vulnerability in the cgit_parse_readme function in ui-summary.c in cgit before 0.9.2, when a readme file is set to a filesystem path, allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.... Read more
- Published: Aug. 09, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3089
Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as... Read more
Affected Products : firefox- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-2209
Cross-site scripting (XSS) vulnerability in the auto-complete widget in htdocs/media/rb/js/reviews.js in Review Board 1.6.x before 1.6.17 and 1.7.x before 1.7.10 allows remote attackers to inject arbitrary web script or HTML via a full name.... Read more
- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-10105
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multipl... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-21331
The Java client for the Datadog API before version 1.0.0-beta.9 has a local information disclosure of sensitive information downloaded via the API using the API Client. The Datadog API is executed on a unix-like system with multiple users. The API is used... Read more
Affected Products : datadog-api-client-java- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-3843
The Linux kernel before 2.6.23-rc1 checks the wrong global variable for the CIFS sec mount option, which might allow remote attackers to spoof CIFS network traffic that the client configured for security signatures, as demonstrated by lack of signing desp... Read more
Affected Products : linux_kernel- Published: Aug. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-20760
Improper input validation vulnerability in User Profile of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of User Profile without the appropriate privilege.... Read more
Affected Products : garoon- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-0709
A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.... Read more
Affected Products : android- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-1692
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to condu... Read more
- Published: Jun. 26, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3473
The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure.... Read more
Affected Products : gd_graphics_library- Published: Jun. 28, 2007
- Modified: Apr. 09, 2025