Latest CVE Feed
-
4.3
MEDIUMCVE-2014-1998
Cross-site scripting (XSS) vulnerability in Nippon Institute of Agroinformatics SOY CMS 1.4.0c and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : soy_cms- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-0584
Session fixation vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to hijack web sessions via unspecified vectors.... Read more
Affected Products : coldfusion- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0815
The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by reading stored cookies.... Read more
- Published: Feb. 06, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1971
Cross-site scripting (XSS) vulnerability in Silex before 2.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : silex- Published: Mar. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-1955
Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : fortiweb- Published: Apr. 30, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5595
The JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly allocate memory for unspecified functions... Read more
- Published: Oct. 30, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3373
Multiple cross-site scripting (XSS) vulnerabilities in the CCM Dialed Number Analyzer interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCu... Read more
Affected Products : unified_communications_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0811
Cross-site scripting (XSS) vulnerability in Blackboard Vista/CE 8.0 SP6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : vista\/ce- Published: Feb. 22, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1914
Multiple cross-site scripting (XSS) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to inject arbitrary web script or HTML via the (1) topic parameter to sw/add_topic.php or (2) nick parameter to sw/chat/message.... Read more
Affected Products : command_school_student_management_system- Published: Feb. 07, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-3364
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard... Read more
Affected Products : prime_security_manager- Published: Dec. 13, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3365
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID C... Read more
Affected Products : prime_security_manager- Published: Feb. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3431
Symantec PGP Desktop 10.x, and Encryption Desktop Professional 10.3.x before 10.3.2 MP2, on OS X uses world-writable permissions for temporary files, which allows local users to bypass intended restrictions on file reading, modification, creation, and per... Read more
- Published: Jun. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-1837
Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors related to "checking new comments."... Read more
Affected Products : komento- Published: Jan. 30, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5604
The ldap_fluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote attackers to bypass authentication via unspecified vectors.... Read more
- Published: Mar. 01, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5766
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.2 and 12.1.0.3 allows... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5510
The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.5), whe... Read more
- Published: Oct. 13, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-0361
ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.... Read more
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-2401
CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing h... Read more
- Published: Jun. 25, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-3433
Cross-site scripting (XSS) vulnerability in the management console in Symantec Data Insight 3.x and 4.x before 4.5 allows remote attackers to inject arbitrary web script or HTML via an unspecified form field, related to an "HTML script injection" issue.... Read more
Affected Products : data_insight- Published: Jun. 27, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3761
Cross-site scripting (XSS) vulnerability in D-Link DAP 1150 with firmware 1.2.94 allows remote attackers to inject arbitrary web script or HTML via the res_buf parameter to index.cgi in the Control/URL-filter section.... Read more
- Published: May. 16, 2014
- Modified: Apr. 12, 2025