Latest CVE Feed
-
4.3
MEDIUMCVE-2015-6530
Cross-site scripting (XSS) vulnerability in OpenText Secure MFT 2013 before 2013 R3 P6 and 2014 before 2014 R2 P2 allows remote attackers to inject arbitrary web script or HTML via the querytext parameter to userdashboard.jsp.... Read more
- Published: Aug. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-7427
The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode packet.... Read more
Affected Products : ntp- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2015-5355
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post-content or (2) post-title parameter to admin/edit.php.... Read more
- Published: Jul. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5519
Cross-site scripting (XSS) vulnerability in the applyConvolution demo in WideImage 11.02.19 allows remote attackers to inject arbitrary web script or HTML via the matrix parameter to demo/index.php.... Read more
Affected Products : wideimage- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5341
mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vecto... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-3110
Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.... Read more
- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-4661
Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the sort parameter to system/authors.... Read more
- Published: Jun. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6088
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."... Read more
- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-6322
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated 3DM file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is cau... Read more
Affected Products : 3d_visual_enterprise_viewer- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-24426
Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this v... Read more
- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-27725
In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones. Zones can be listed via TMSH, iControl or SNMP; only users with access to ... Read more
- Published: Dec. 24, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-4236
Cisco AsyncOS on Email Security Appliance (ESA) devices with software 8.5.6-073, 8.5.6-074, and 9.0.0-461, when clustering is enabled, allows remote attackers to cause a denial of service (clustering and SSH outage) via a packet flood, aka Bug IDs CSCur13... Read more
Affected Products : email_security_appliance email_security_appliance_firmware email_security_appliance- Published: Jul. 10, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8053
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8052.... Read more
Affected Products : coldfusion- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1556
Cross-site scripting (XSS) vulnerability in Synology Photo Station 5 for DiskStation Manager (DSM) 3.2-1955 allows remote attackers to inject arbitrary web script or HTML via the name parameter to photo/photo_one.php.... Read more
- Published: Sep. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3756
Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4 on Windows and Mac OS X 10.4 through 10.4.10, allows remote attackers to obtain sensitive information via a crafted web page that identifies the URL of the parent window, even when the pa... Read more
- Published: Sep. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-6086
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8052
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 18 and 11 before Update 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-8053.... Read more
Affected Products : coldfusion- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3742
WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-alike ch... Read more
- Published: Aug. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-4449
The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free t... Read more
- Published: Feb. 05, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-2321
Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the email field.... Read more
- Published: Aug. 13, 2015
- Modified: Apr. 12, 2025