Latest CVE Feed
-
4.3
MEDIUMCVE-2016-2953
IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the network.... Read more
Affected Products : connections- Published: Nov. 30, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1617
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply w... Read more
Affected Products : chrome- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-1231
Inappropriate implementation in Autofill in Google Chrome on Android prior to 111.0.5563.64 allowed a remote attacker to potentially spoof the contents of the omnibox via a crafted HTML page. (Chromium security severity: Medium)... Read more
- Published: Mar. 07, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-1626
The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PD... Read more
- Published: Feb. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-30946
A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b_73a_69a_08 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-specified webserver.... Read more
Affected Products : script_security- Published: May. 17, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-3163
The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack... Read more
Affected Products : easy_property_listings- Published: Sep. 12, 2024
- Modified: Sep. 26, 2024
-
4.3
MEDIUMCVE-2016-1860
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.... Read more
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1664
The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers to ... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1658
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.... Read more
- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1957
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.... Read more
Affected Products : firefox firefox_esr thunderbird leap linux opensuse suse_package_hub_for_suse_linux_enterprise- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-17184
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an integer overflow vulnerability. Due to i... Read more
Affected Products : dp300_firmware te60_firmware rp200_firmware te30_firmware te40_firmware te50_firmware te30 te40 te50 te60 +2 more products- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-0421
The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a ZIPARCHIVE::FL_UNCHANGED argument, which might allow context-dependent attackers to cause a denial of service (NULL pointer dereference)... Read more
Affected Products : php- Published: Mar. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-6477
Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : nordex_control_2_scada- Published: Oct. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6479
ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspeci... Read more
- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0583
Unspecified vulnerability in the Oracle CRM Technology Foundation component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to BIS Common Components, a different vulnerability than CVE-2016-0579, CVE-20... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6244
The dissect_zbee_secure function in epan/dissectors/packet-zbee-security.c in the ZigBee dissector in Wireshark 1.12.x before 1.12.7 improperly relies on length fields contained in packet data, which allows remote attackers to cause a denial of service (a... Read more
- Published: Aug. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0463
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote attackers to affect confidentiality via unknown vectors related to Portal.... Read more
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6466
Cross-site scripting (XSS) vulnerability in the Diagnosis Ping feature in the administrative web interface on Moxa EDS-405A and EDS-408A switches with firmware before 3.6 allows remote attackers to inject arbitrary web script or HTML via an unspecified fi... Read more
- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0508
Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect integrity via unknown vectors related to Learner Administration.... Read more
Affected Products : ilearning- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-0580
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : coldfusion- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025