Latest CVE Feed
-
4.3
MEDIUMCVE-2011-4897
Tor before 0.2.2.25-alpha, when configured as a relay without the Nickname configuration option, uses the local hostname as the Nickname value, which allows remote attackers to obtain potentially sensitive information by reading this value.... Read more
- Published: Dec. 23, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4819
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management and Asset Management Essentials 6.2, 7.1, and 7.5 allow remote attackers to inject arbitrary web script or HTML via the uisesionid parameter to (1) maximo.jsp or (2) the de... Read more
- Published: Mar. 13, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4822
Multiple cross-site scripting (XSS) vulnerabilities in the user profile feature in Atlassian FishEye before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) snippets in a user comment, which is not properly handled in a Confluen... Read more
Affected Products : fisheye- Published: Dec. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4850
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not include the HTTPOnly flag in a Set-Cookie header for a cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this coo... Read more
- Published: Dec. 16, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4820
IBM Rational Asset Manager 7.5 could allow a remote attacker to bypass security restrictions. An attacker could exploit this vulnerability using the UID parameter to modify another user's preferences.... Read more
Affected Products : rational_asset_manager- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-4805
Cross-site scripting (XSS) vulnerability in pubDBLogon.jsp in SAP Crystal Report Server 2008 allows remote attackers to inject arbitrary web script or HTML via the service parameter.... Read more
Affected Products : crystal_reports_server- Published: Dec. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-22329
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vulnerable to server-side request forgery (SSRF). By sending a specially crafted request, an attacker could exploit this vulnerability to ... Read more
Affected Products : websphere_application_server- Published: Apr. 17, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5567
Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject arbitrary web script or HTML via crafted event location... Read more
- Published: Apr. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5990
Multiple cross-site scripting (XSS) vulnerabilities in Health Monitor Login pages in Cisco Prime Network Control System (NCS) and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ... Read more
- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5584
The Table of Contents module 6.x-3.x before 6.x-3.8 for Drupal does not properly check node permissions, which allows remote attackers to read a node's headers by accessing a table of contents block.... Read more
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-9179
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5).... Read more
Affected Products : gitlab- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-1870
Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-and-drop operation.... Read more
- Published: Feb. 06, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5591
Cross-site scripting (XSS) vulnerability in the Zero Point module 6.x-1.x before 6.x-1.18 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the path aliases.... Read more
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0047
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."... Read more
Affected Products : mediawiki- Published: Feb. 04, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4827
Multiple cross-site scripting (XSS) vulnerabilities in AutoSec Tools V-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) p parameter to redirect.php and (2) box parameter to includes/TrueColorPicker/index.php, which is not ... Read more
Affected Products : v-cms- Published: Dec. 15, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-5765
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5767.... Read more
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5606
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.9 and 4.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) file name to apps/files_versions/js/versions.js or (2) apps/files/js/filelist.js; or (3) event... Read more
- Published: Dec. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4814
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.p... Read more
Affected Products : dolibarr_erp\/crm- Published: Dec. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2285
Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.... Read more
Affected Products : libtiff- Published: Jul. 01, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-5625
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by readi... Read more
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025