Latest CVE Feed
-
4.3
MEDIUMCVE-2021-21183
Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.... Read more
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-7398
main/java/com/ning/http/client/AsyncHttpClientConfig.java in Async Http Client (aka AHC or async-http-client) before 1.9.0 does not require a hostname match during verification of X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS... Read more
- Published: Jun. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-7002
Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject arbitrary web script or HTML via the g_language parameter.... Read more
Affected Products : livezilla- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-8720
An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can inject a payload in the bkpath parameter which will be co... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-6559
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.... Read more
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-6037
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not ... Read more
Affected Products : mahara- Published: Nov. 24, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-21091
Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Out-of-bounds read vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in ... Read more
- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21189
Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.... Read more
- Published: Mar. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-4053
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.... Read more
- Published: Apr. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5624
The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.... Read more
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-8475
FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and preven... Read more
Affected Products : freebsd- Published: Nov. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-21438
Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.... Read more
- Published: Mar. 22, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-10105
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multipl... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2021-20762
Improper input validation vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated to alter the data of E-mail without the appropriate privilege.... Read more
Affected Products : garoon- Published: Aug. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-21331
The Java client for the Datadog API before version 1.0.0-beta.9 has a local information disclosure of sensitive information downloaded via the API using the API Client. The Datadog API is executed on a unix-like system with multiple users. The API is used... Read more
Affected Products : datadog-api-client-java- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5326
Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.... Read more
- Published: Nov. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-20747
Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 allows a remote attacker to lead a user to access an arbitrary website via the vulnerab... Read more
Affected Products : retty- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3146
Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scripting (XSS) attacks via control characters in the link scheme to the clean_html function.... Read more
Affected Products : lxml- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6636
The FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 31.0.1650.63, makes an incorrect check for an empty document during presentation of a modal dialog, which allows remote atta... Read more
Affected Products : chrome- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5669
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-boun... Read more
Affected Products : freetype- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025