Latest CVE Feed
-
4.3
MEDIUMCVE-2006-4255
Cross-site scripting (XSS) vulnerability in horde/imp/search.php in Horde IMP H3 before 4.1.3 allows remote attackers to include arbitrary web script or HTML via multiple unspecified vectors related to folder names, as injected into the vfolder_label form... Read more
- Published: Aug. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1970
Cross-site scripting (XSS) vulnerability in classifieds/viewcat.cgi in KCScripts Classifieds, distributed individually and as part of Portal Pack 6.0 and earlier, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.... Read more
Affected Products : portal_pack- Published: Apr. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-6102
Missing confusable characters in Internationalization in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.... Read more
- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-3240
Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.... Read more
Affected Products : dotproject- Published: Jun. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-1044
In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.... Read more
Affected Products : moodle- Published: Jan. 22, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-1891
Cross-site scripting (XSS) vulnerability in Martin Scheffler betaboard 0.1 allows remote attackers to inject arbitrary web script or HTML via a user's profile, possibly using the FormVal_profile parameter. NOTE: it is not clear whether this is a distribu... Read more
Affected Products : betaboard- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-2416
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0591
Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by usin... Read more
- Published: Feb. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-6112
Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.... Read more
Affected Products : debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation chrome- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-5170
It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thund... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-0460
Cross-site scripting (XSS) vulnerability in api.php in (1) MediaWiki 1.11 through 1.11.0rc1, 1.10 through 1.10.2, 1.9 through 1.9.4, and 1.8; and (2) the BotQuery extension for MediaWiki 1.7 and earlier; when Internet Explorer is used, allows remote attac... Read more
- Published: Jan. 25, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-1925
Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce ... Read more
Affected Products : cutenews- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3261
Cross-site scripting (XSS) vulnerability in Trend Micro Control Manager (TMCM) 3.5 allows remote attackers to inject arbitrary web script or HTML via the username field on the login page, which is not properly sanitized before being displayed in the error... Read more
Affected Products : control_manager- Published: Jun. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3297
Cross-site scripting (XSS) vulnerability in error.php in UebiMiau Webmail 2.7.10 and earlier allows remote attackers to inject arbitrary web script or HTML via the icq parameter. NOTE: the provenance of this information is unknown; the details are obtain... Read more
Affected Products : uebimiau- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-0165
Cross-site request forgery (CSRF) vulnerability in Ikiwiki before 2.42 allows remote attackers to modify user preferences, including passwords, via the (1) preferences and (2) edit forms.... Read more
Affected Products : ikiwiki- Published: Apr. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-20067
A renderer initiated back navigation was incorrectly allowed to cancel a browser initiated one in Navigation in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to confuse the user about the origin of the current page via a crafted HTML page.... Read more
Affected Products : chrome- Published: Jan. 09, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-0005
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.... Read more
- Published: Jan. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-4329
IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 20.0.0.4 could allow a remote, authenticated attacker to obtain sensitive information, caused by improper parameter checking. This could be exploited to conduct spoofing atta... Read more
Affected Products : websphere_application_server- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-0614
Cross-site scripting (XSS) vulnerability in search.php of Gallery 1.1 through 1.3.4 allows remote attackers to insert arbitrary web script via the searchstring parameter.... Read more
Affected Products : gallery- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3295
Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter.... Read more
Affected Products : open_guestbook- Published: Jun. 29, 2006
- Modified: Apr. 03, 2025