Latest CVE Feed
-
4.3
MEDIUMCVE-2013-4202
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expa... Read more
- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5501
Cross-site scripting (XSS) vulnerability in the oraservice page in Cisco MediaSense allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuj23328.... Read more
Affected Products : mediasense- Published: Sep. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-1996
Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.0 allows remote attackers to modify data via unknown vectors.... Read more
Affected Products : systems_insight_manager- Published: Mar. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4193
typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.... Read more
Affected Products : plone- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5422
The Web Client in IBM Rational ClearQuest 7.1 through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2, when a multi-database dataset exists, allows remote attackers to read database names via unspecified vectors.... Read more
- Published: Dec. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5438
Cross-site scripting (XSS) vulnerability in the web server in IBM Flex System Manager (FSM) 1.1.0 through 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : flex_system_manager- Published: Dec. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5449
Cross-site scripting (XSS) vulnerability in workingSet.jsp in IBM Eclipse Help System (IEHS), as used in the installable InfoCenter component in IBM FileNet Content Manager 4.5.1, 5.0.0, 5.1.0, and 5.2.0, allows remote attackers to inject arbitrary web sc... Read more
Affected Products : filenet_content_manager- Published: Dec. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-25394
A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' character.... Read more
Affected Products : rt-thread- Published: Mar. 27, 2024
- Modified: Apr. 16, 2025
-
4.3
MEDIUMCVE-2013-4179
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issu... Read more
- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-25132
A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive times... Read more
Affected Products :- Published: Mar. 19, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2013-5454
IBM WebSphere Portal 6.0 through 6.0.1.7, 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF25, and 8.0 through 8.0.0.1 CF08 allows remote attackers to read arbitrary files via a modified URL.... Read more
Affected Products : websphere_portal- Published: Nov. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5497
The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly handle user tokens, which allows remote attackers to cause a denial of service (intermittent MainApp hang) via a crafted management-interf... Read more
- Published: Sep. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4276
Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility.... Read more
Affected Products : little_cms_color_engine- Published: Sep. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2143
The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-d... Read more
- Published: Jul. 05, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0867
PostgreSQL 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 truncates the common name to only 32 characters when verifying SSL certificates, which allows remote attackers to spoof connections when the host name is exactly 32 characters.... Read more
- Published: Jul. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4171
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RSS and (2) Atom feed templates.... Read more
Affected Products : roller- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1524
Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) before 2.3 allows remote attackers to inject arbitrary web script or HTML via the username field, as demonstrated by injecting an IFRAME e... Read more
Affected Products : liveupdate_administrator- Published: Mar. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5519
Cross-site scripting (XSS) vulnerability in the management interface on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuf77810.... Read more
Affected Products : wireless_lan_controller- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5462
IBM/ECMClient/configure/explodedformat/navigator/header.jsp in IBM Content Navigator 2.0.0, 2.0.1 before 2.0.1.2-ICN-FP002, and 2.0.2 before 2.0.2.1-ICN-FP001 allows remote attackers to conduct clickjacking attacks via vectors involving FRAME elements.... Read more
Affected Products : content_navigator- Published: Dec. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3866
Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.... Read more
- Published: Sep. 29, 2011
- Modified: Apr. 11, 2025