Latest CVE Feed
-
4.3
MEDIUMCVE-2020-8275
Citrix Secure Mail for Android before 20.11.0 suffers from improper access control allowing unauthenticated access to read limited calendar related data stored within Secure Mail. Note that a malicious app would need to be installed on the Android device ... Read more
Affected Products : secure_mail- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-4784
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.... Read more
Affected Products : moodle- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-8284
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for ... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire peoplesoft_enterprise_peopletools macos clustered_data_ontap mac_os_x sinec_infrastructure_network_services +19 more products- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-5718
Cross-site scripting (XSS) vulnerability in error.php in phpMyAdmin 2.6.4 through 2.9.0.2 allows remote attackers to inject arbitrary web script or HTML via UTF-7 or US-ASCII encoded characters, which are injected into an error message, as demonstrated by... Read more
Affected Products : phpmyadmin- Published: Nov. 04, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-6527
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.... Read more
- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-6529
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.... Read more
- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-3339
Multiple cross-site scripting (XSS) vulnerabilities in forum/include/error/autherror.cfm in FuseTalk Basic, Standard, Enterprise, and ColdFusion allow remote attackers to inject arbitrary web script or HTML via the (1) FTVAR_LINKP and (2) FTVAR_URLP param... Read more
Affected Products : fusetalk- Published: Jun. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2155
Multiple cross-site scripting (XSS) vulnerabilities in zc/publisher/html.rb in ZoneCheck 2.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) xmlnode.value, (2) zc-error text, (3) $zc_version, (4) domainname in a ... Read more
Affected Products : zonecheck- Published: Jun. 03, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-0120
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows Uniscribe Information Disclosure Vulnerability... Read more
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2015-2941
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM, allows remote attackers to inject arbitrary web script or HTML via an invalid parameter in a wddx format request to api.ph... Read more
Affected Products : mediawiki- Published: Apr. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2932
Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an animated href XLink element.... Read more
Affected Products : mediawiki- Published: Apr. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5828
The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5309
Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters) escape sequence with a large parameter value, which tr... Read more
- Published: Dec. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-2072
Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/t... Read more
Affected Products : hana- Published: Feb. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-5080
Cross-site scripting (XSS) vulnerability in the search function in Six Apart Movable Type 3.3 to 3.32, and Movable Type Enterprise 1.01 and 1.02, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 29, 2006
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-2063
Integer overflow in unace 1.2b allows remote attackers to cause a denial of service (crash) via a small file header in an ace archive, which triggers a buffer overflow.... Read more
Affected Products : unace- Published: Mar. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5460
Cross-site scripting (XSS) vulnerability in app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the title (cls.name variable) when creating a classification.... Read more
Affected Products : snorby- Published: Jul. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5537
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerabil... Read more
- Published: Aug. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4518
The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors... Read more
Affected Products : firefox- Published: Nov. 05, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-2596
The OJPEGPostDecode function in tif_ojpeg.c in LibTIFF 3.9.0 and 3.9.2, as used in tiff2ps, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF image, related to "downsampled OJPEG input."... Read more
Affected Products : libtiff- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025