Latest CVE Feed
-
4.3
MEDIUMCVE-2006-4825
Multiple cross-site scripting (XSS) vulnerabilities in cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) ti, (2) bi, or (3) cbgi parameters.... Read more
Affected Products : php_event_calendar- Published: Sep. 15, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-5556
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 does not recognize attack patterns designed to operate against web pages that are encoded with utf-7, which allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by ... Read more
Affected Products : internet_explorer- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5487
Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : text_link_sales- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-4843
Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified "code sequences" that bypass the protect... Read more
Affected Products : lotus_domino- Published: Mar. 29, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-0980
Multiple cross-site scripting (XSS) vulnerabilities in Jay Eckles CGI Calendar 2.7 allow remote attackers to inject arbitrary web script or HTML via the year parameter in (1) index.cgi and (2) viewday.cgi.... Read more
Affected Products : cgi_calendar- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-5552
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks via a CRLF sequence in conjunction with a crafted Content-Type header, as demonstrated by a header with a utf-7... Read more
Affected Products : internet_explorer- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3881
Cross-site scripting (XSS) vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter in a request for the top-level URI. NOTE: the id parameter in index.php, and the type and s... Read more
Affected Products : musicbox- Published: Jul. 27, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-0958
Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 stores an exception for a hostname when the user accepts an untrusted Exchange server certificate, which causes it to be accepted without prompting in future usage and allows... Read more
- Published: Jun. 19, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2020-12864
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.... Read more
- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-3820
Cross-site scripting (XSS) vulnerability in loudblog/index.php in Loudblog before 0.5 allows remote attackers to inject arbitrary web script or HTML via the page parameter.... Read more
Affected Products : loudblog- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-5555
Microsoft Internet Explorer 8.0 Beta 2 relies on the XDomainRequestAllowed HTTP header to authorize data exchange between domains, which allows remote attackers to bypass the product's XSS Filter protection mechanism, and conduct XSS and cross-domain atta... Read more
Affected Products : internet_explorer- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-3817
Cross-site scripting (XSS) vulnerability in Novell GroupWise WebAccess 6.5 and 7 before 20060727 allows remote attackers to inject arbitrary web script or HTML via an encoded SCRIPT element in an e-mail message with the UTF-7 character set, as demonstrate... Read more
Affected Products : groupwise_webaccess- Published: Aug. 11, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3765
Multiple cross-site scripting (XSS) vulnerabilities in Huttenlocher Webdesign hwdeGUEST 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated by the "name input" field in new_entry.php.... Read more
Affected Products : hwdeguest- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2006-3821
Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in (a) index_list.php and (2) year, (3) month, and (4) day parameter in (b) registration.php.... Read more
Affected Products : atutor- Published: Jul. 25, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2020-13335
Improper group membership validation when deleting a user account in GitLab >=7.12 allows a user to delete own account without deleting/transferring their group.... Read more
Affected Products : gitlab- Published: Oct. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-12863
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.... Read more
- Published: Jun. 24, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-5566
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : phpmultiplenewsletters- Published: Dec. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-5214
Cross-site scripting (XSS) vulnerability in service/calendrier.php in ClanLite 2.2006.05.20 allows remote attackers to inject arbitrary web script or HTML via the annee parameter.... Read more
Affected Products : clanlite- Published: Nov. 24, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0793
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code ... Read more
- Published: Apr. 09, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2006-1131
Cross-site scripting (XSS) vulnerability in read.php in bitweaver CMS 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the comment_title parameter.... Read more
Affected Products : bitweaver- Published: Mar. 10, 2006
- Modified: Apr. 03, 2025