Latest CVE Feed
-
4.3
MEDIUMCVE-2013-0201
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to core/lostpassword/templates/resetpassword.php, (2) mime parameter to apps/... Read more
- Published: Mar. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2005-1189
Cross-site scripting (XSS) vulnerability in WebcamXP PRO v2.16.468 and earlier allows remote attackers to inject arbitrary web script or HTML via the chat name, as demonstrated by using an IFRAME to redirect users to other sites.... Read more
Affected Products : webcamxp_pro- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2024-23520
Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0. ... Read more
Affected Products : popupally- Published: Mar. 26, 2024
- Modified: Mar. 20, 2025
-
4.3
MEDIUMCVE-2005-1118
Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary web script or HTML via the postdata parameter.... Read more
Affected Products : authentication_agent_for_web- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-0013
Multiple cross-site scripting (XSS) vulnerabilities in the HTML Manager Interface in Apache Tomcat 5.5 before 5.5.32, 6.0 before 6.0.30, and 7.0 before 7.0.6 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the display-na... Read more
Affected Products : tomcat- Published: Feb. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0215
oxenstored in Xen 4.1.x, Xen 4.2.x, and xen-unstable does not properly consider the state of the Xenstore ring during read operations, which allows guest OS users to cause a denial of service (daemon crash and host-control outage, or memory consumption) o... Read more
Affected Products : xen- Published: Mar. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0124
Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in ASKIA askiaweb allow remote attackers to inject arbitrary web script or HTML via the (1) Number or (2) UpdatePage parameter to WebProd/cgi-bin/AskiaExt.dll.... Read more
Affected Products : askiaweb- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0176
The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" pac... Read more
Affected Products : libssh- Published: Feb. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0125
Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File parameter.... Read more
Affected Products : c2_webresource- Published: Apr. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3670
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metach... Read more
- Published: Jul. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-0104
Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.... Read more
- Published: Jan. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2010-0163
Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execu... Read more
- Published: Mar. 23, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3037
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.... Read more
Affected Products : simatic_s7-1200_cpu_1211c_firmware simatic_s7-1200_cpu_1212c_firmware simatic_s7-1200_cpu_1214c_firmware simatic_s7-1200_cpu_1215c_firmware simatic_s7-1200_cpu_1217c_firmware simatic_s7-1200_firmware simatic_s7-1200_cpu_1212fc_firmware simatic_s7-1200_cpu_1214_fc_firmware simatic_s7-1200_cpu_1215_fc_firmware simatic_s7-1200 +8 more products- Published: Sep. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-2812
Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.35, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) the action parameter.... Read more
Affected Products : hlstats- Published: May. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2018-0855
The Microsoft Windows Embedded OpenType (EOT) font engine in Microsoft Windows 7 SP1 and Windows Server 2008 R2 allows information disclosure, due to how the Windows EOT font engine handles embedded fonts, aka "Windows EOT Font Engine Information Disclosu... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-5017
Interactions with the OS in Google Chrome prior to 56.0.2924.76 for Mac insufficiently cleared video memory, which allowed a remote attacker to possibly extract image fragments on systems with GeForce 8600M graphics chips via a crafted HTML page.... Read more
Affected Products : chrome- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2018-8578
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint... Read more
- Published: Nov. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-0001
The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser ... Read more
- Published: Jan. 09, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-6658
Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName configuration in snmpd.conf. NOTE: this entry was SPLIT from... Read more
Affected Products : spiceworks- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-6131
Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via the @action parameter to support/issue1.... Read more
Affected Products : roundup- Published: Apr. 11, 2014
- Modified: Apr. 12, 2025