Latest CVE Feed
-
4.3
MEDIUMCVE-2007-4165
Cross-site scripting (XSS) vulnerability in index.php in the Blue Memories theme 1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757 and CVE-2007-4014. NOTE: the ... Read more
Affected Products : blue_memories_theme- Published: Aug. 07, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4336
Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827, as packaged in Microsoft DirectX Media 6.0 SDK, allows remote attackers to execute arbitrary code via a l... Read more
Affected Products : directx_media- Published: Aug. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2915
Cross-site scripting (XSS) vulnerability in RM EasyMail Plus allows remote attackers to inject arbitrary web script or HTML via the title field in an email.... Read more
Affected Products : rm_easymail_plus- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4297
Multiple cross-site scripting (XSS) vulnerabilities in yorumkaydet.asp in Dersimiz Haber Ekleme Modulu allow remote attackers to inject arbitrary web script or HTML via the (1) yazan, (2) mail, and (3) yorum parameters. NOTE: some of these details are ob... Read more
Affected Products : dersimiz_haber_ekleme_modulu- Published: Aug. 10, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3131
Cross-site scripting (XSS) vulnerability in add_comment.php in Light Blog 4.1 before 20070606 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : light_blog- Published: Jun. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-1611
Cross-site scripting (XSS) vulnerability in the RSS reader in a certain SOURCENEXT product, probably IKANARI JIJYOU 1.0.0 and 1.0.1, allows remote attackers to inject arbitrary web script or HTML via the title of an article in a feed.... Read more
Affected Products : ikanari_jijyou- Published: Mar. 22, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-4337
The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.... Read more
Affected Products : cups-filters- Published: Jun. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3645
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extensi... Read more
- Published: Jul. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-5369
Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more
Affected Products : enigmail- Published: Sep. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-4350
Cross-site scripting (XSS) vulnerability in the management interface in HP SiteScope 9.0 build 911 allows remote attackers to inject arbitrary web script or HTML via an SNMP trap message.... Read more
Affected Products : sitescope- Published: Oct. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-6059
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Eng... Read more
- Published: Oct. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-4363
Multiple cross-site scripting (XSS) vulnerabilities in the nodereference module in Drupal Content Construction Kit (CCK) before 4.7.x-1.6, and 5.x before 5.x-1.6 ,allow remote attackers to inject arbitrary web script or HTML via nodereference fields, when... Read more
Affected Products : content_construction_kit- Published: Aug. 15, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4387
Cross-site request forgery (CSRF) vulnerability in /xslt in 2wire 1701HG and 2071 Gateway routers, with 3.17.5 and 5.29.51 software, allows remote attackers to perform certain configuration changes as administrators.... Read more
- Published: Aug. 17, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3653
Multiple cross-site scripting (XSS) vulnerabilities in Farsi Script (aka FaScript) FaName 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) key or (2) desc parameter to index.php, or (3) the name parameter to page.php.... Read more
Affected Products : faname- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3571
The Apache Web Server as used in Novell NetWare 6.5 and GroupWise allows remote attackers to obtain sensitive information via a certain directive to Apache that causes the HTTP-Header response to be modified, which may reveal the server's internal IP addr... Read more
- Published: Jul. 05, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-10332
A missing permission check in Jenkins ElectricFlow Plugin 1.1.5 and earlier in Configuration#doTestConnection allowed users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials.... Read more
Affected Products : electricflow- Published: Jun. 11, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4316
The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device has a certain default password, which allows remote attackers to perform administrative actions.... Read more
- Published: Aug. 13, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4252
Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String allows remote attackers to create or overwrite arbitrary files via a full pathname in the first argument to the SaveToFile method, a d... Read more
Affected Products : asp_string- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4248
The CallCmd function in toolbar_gaming.dll in the Toolbar Gaming toolbar for Internet Explorer allows remote attackers to cause a denial of service (NULL dereference and browser crash) via unspecified vectors.... Read more
Affected Products : toolbar_gaming- Published: Aug. 08, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-5339
The core_enrol_get_enrolled_users web service in enrol/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 does not properly implement group-based access restrictions, which allows remote authenticated... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025