Latest CVE Feed
-
4.3
MEDIUMCVE-2006-1720
Cross-site scripting (XSS) vulnerability in search.php in SaphpLesson 3.0 allows remote attackers to inject arbitrary web script or HTML via the Word parameter. NOTE: it is possible that this issue is resultant from SQL injection.... Read more
Affected Products : saphplesson- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-2963
Cross-site scripting (XSS) vulnerability in Suchergebnisse.asp in Cabacos Web CMS 3.8.498 and earlier allows remote attackers to inject arbitrary web script or HTML via the suchtext parameter.... Read more
Affected Products : cabacos_web_cms- Published: Jun. 12, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2007-5340
Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.... Read more
- Published: Oct. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5302
Multiple cross-site scripting (XSS) vulnerabilities in HP System Management Homepage (SMH) in HP-UX B.11.11, B.11.23, and B.11.31, and SMH before 2.1.10 for Linux and Windows, allow remote attackers to inject arbitrary web script or HTML via unspecified v... Read more
Affected Products : hp-ux- Published: Oct. 09, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-3962
Google Chrome before 17.0.963.46 does not properly perform path clipping, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.... Read more
Affected Products : chrome- Published: Feb. 09, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-1681
Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is gen... Read more
Affected Products : cherokee_httpd- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-5688
MediaWiki 1.8.1, and other versions before 1.13.3, when the wgShowExceptionDetails variable is enabled, sometimes provides the full installation path in a debugging message, which might allow remote attackers to obtain sensitive information via unspecifie... Read more
Affected Products : mediawiki- Published: Dec. 19, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-8498
Microsoft Edge in Windows 10 1607 and 1703, and Windows Server 2016 allows an attacker to read data not intended to be disclosed when Edge allows JavaScript XML DOM objects to detect installed browser extensions, aka "Microsoft Edge Information Disclosure... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2006-1682
Cross-site scripting (XSS) vulnerability in webplus.exe in TalentSoft Web+Shop 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the deptname parameter, possibly involving the webpshop/ department.wml script.... Read more
Affected Products : web\+_shop- Published: Apr. 11, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-1731
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called wit... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-4546
The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly update another Identity Management replica, which causes inconsistent Certificate Revocation Lists ... Read more
Affected Products : enterprise_linux- Published: Apr. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4100
The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.3 does not initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed ... Read more
Affected Products : wireshark- Published: Nov. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-6849
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.... Read more
Affected Products : duckduckgo- Published: Apr. 01, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-4312
Multiple cross-site scripting (XSS) vulnerabilities in the commenting system in Review Board before 1.5.7 and 1.6.x before 1.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) diff viewer or (2) screenshot comp... Read more
Affected Products : review_board- Published: Nov. 24, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-4730
Buffer overflow in the compNewPixmap function in compalloc.c in the Composite extension for the X.org X11 server before 1.4 allows local users to execute arbitrary code by copying data from a large pixel depth pixmap into a smaller pixel depth pixmap.... Read more
Affected Products : xorg-server- Published: Sep. 11, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-4353
The (1) av_image_fill_pointers, (2) vp5_parse_coeff, and (3) vp6_parse_coeff functions in FFmpeg 0.5.x before 0.5.7, 0.6.x before 0.6.4, 0.7.x before 0.7.9, and 0.8.x before 0.8.8; and in Libav 0.5.x before 0.5.6, 0.6.x before 0.6.4, and 0.7.x before 0.7.... Read more
- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-1657
Cross-site scripting (XSS) vulnerability in index.php in Chucky A. Ivey N.T. 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not filtered when the administrator views the "Login Log" page.... Read more
Affected Products : n.t.- Published: Apr. 07, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3321
Multiple cross-site scripting (XSS) vulnerabilities in openforum.asp in OpenForum 1.2 Beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ofdisp and (2) ofmsgid parameters.... Read more
Affected Products : openforum- Published: Jun. 30, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-1711
The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers ... Read more
- Published: Aug. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-1936
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a u... Read more
Affected Products : gitlab- Published: Jul. 11, 2023
- Modified: Nov. 21, 2024