Latest CVE Feed
-
4.3
MEDIUMCVE-2014-1777
Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."... Read more
Affected Products : internet_explorer- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0081
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via t... Read more
- Published: Feb. 20, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4411
Review Board: URL processing gives unauthorized users access to review lists... Read more
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4193
typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.... Read more
Affected Products : plone- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2022-22670
An access issue was addressed with improved access restrictions. This issue is fixed in tvOS 15.4, iOS 15.4 and iPadOS 15.4, watchOS 8.5. A malicious application may be able to identify what other applications a user has installed.... Read more
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0413
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via vectors related to HTTP Request Handling, a different vulnerability than CVE-2014-0426.... Read more
Affected Products : fusion_middleware- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0426
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via vectors related to HTTP Request Handling, a different vulnerability than CVE-2014-0413.... Read more
Affected Products : fusion_middleware- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-1996
Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.0 allows remote attackers to modify data via unknown vectors.... Read more
Affected Products : systems_insight_manager- Published: Mar. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4202
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expa... Read more
- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4453
Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.... Read more
Affected Products : ldap_account_manager- Published: Nov. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-1000398
The remote API in Jenkins 2.73.1 and earlier, 2.83 and earlier at /computer/(agent-name)/api showed information about tasks (typically builds) currently running on that agent. This included information about tasks that the current user otherwise has no ac... Read more
Affected Products : jenkins- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-0434
Unspecified vulnerability in the Oracle Agile Product Lifecycle Management for Process component in Oracle Supply Chain Products Suite 6.0, 6.1, and 6.1.1 allows remote attackers to affect integrity via unknown vectors related to Installation.... Read more
Affected Products : supply_chain_products_suite- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1972
Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files... Read more
- Published: Jun. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4399
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by reg... Read more
Affected Products : libvirt- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-3690
Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Proxy Granting Ticket IOU (PGTiou) parameter to the callback function i... Read more
- Published: Oct. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-0433
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.13 and earlier allows remote attackers to affect availability via unknown vectors related to Thread Pooling.... Read more
Affected Products : mysql- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4238
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitra... Read more
- Published: Aug. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4389
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handl... Read more
- Published: Oct. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-25686
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers, so ... Read more
- Published: Jan. 20, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4415
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) whereCriteria variable in a software channels search; (2) end_year, (3) star... Read more
- Published: Feb. 14, 2014
- Modified: Apr. 11, 2025