Latest CVE Feed
-
4.3
MEDIUMCVE-2011-1330
Cross-site scripting (XSS) vulnerability in WeblyGo 5.0 Pro/LE, 5.02 Pro/LE, 5.03 Pro/LE, 5.04 Pro/LE, and 5.10 Pro/LE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : weblygo- Published: Jun. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0273
Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal'... Read more
Affected Products : drupal- Published: Jan. 15, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-3444
Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV data by terminating an encrypted connection and then sniffing the network.... Read more
- Published: Feb. 02, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3483
Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed capture file that leads to an invalid root tvbuff, related to a "buffer exception handling vulnerability."... Read more
Affected Products : wireshark- Published: Sep. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3246
Google Chrome before 6.0.472.53 does not properly handle the _blank value for the target attribute of unspecified elements, which allows remote attackers to bypass the pop-up blocker via unknown vectors.... Read more
Affected Products : chrome- Published: Sep. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3452
Internet Sharing in Apple Mac OS X before 10.7.3 does not preserve the Wi-Fi configuration across software updates, which allows remote attackers to obtain sensitive information by leveraging the lack of a WEP password for a Wi-Fi network.... Read more
- Published: Feb. 02, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3441
libinfo in Apple iOS before 5.0.1 does not properly formulate domain-name queries, which allows remote attackers to obtain sensitive information via a crafted DNS hostname.... Read more
Affected Products : iphone_os- Published: Nov. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-4465
Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect (LMC) 6.1.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden redirect URL.... Read more
Affected Products : lotus_mobile_connect- Published: Nov. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-15792
A vulnerability has been identified in Desigo Insight (All versions). The web service does not properly apply input validation for some query parameters in a reserved area. This could allow an authenticated attacker to retrieve data via a content-based bl... Read more
Affected Products : desigo_insight- Published: Oct. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-6192
Multiple cross-site scripting (XSS) vulnerabilities in unspecified Portlets in Sun Java System Portal Server 7.0 and 7.1 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : java_system_portal_server- Published: Feb. 19, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2012-2694
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows... Read more
- Published: Jun. 22, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-5448
Madwifi 0.9.3.2 and earlier allows remote attackers to cause a denial of service (panic) via a beacon frame with a large length value in the extended supported rates (xrates) element, which triggers an assertion error, related to net80211/ieee80211_scan_a... Read more
Affected Products : madwifi- Published: Oct. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-50779
Missing permission checks in Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified token.... Read more
Affected Products : paaslane_estimate- Published: Dec. 13, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-2302
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Single Sign On.... Read more
Affected Products : e-business_suite- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-40766
Adobe Character Animator version 4.4 (and earlier versions) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitati... Read more
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2011-1951
lib/logmatcher.c in Balabit syslog-ng before 3.2.4, when the global flag is set and when using PCRE 8.12 and possibly other versions, allows remote attackers to cause a denial of service (memory consumption) via a message that does not match a regular exp... Read more
- Published: Jul. 11, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2222
Session fixation vulnerability in WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to hijack web sessions via unspecified vectors.... Read more
- Published: Aug. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1398
The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a craf... Read more
Affected Products : php- Published: Aug. 30, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3482
The csnStreamDissector function in epan/dissectors/packet-csn1.c in the CSN.1 dissector in Wireshark 1.6.x before 1.6.2 does not initialize a certain structure member, which allows remote attackers to cause a denial of service (application crash) via a ma... Read more
Affected Products : wireshark- Published: Sep. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-2227
Cross-site scripting (XSS) vulnerability in Novell Identity Manager (aka IDM) User Application 3.5.0, 3.5.1, 3.6.0, 3.6.1, 3.7.0, and 4.0.0, and Identity Manager Roles Based Provisioning Module 3.6.0, 3.6.1, 3.7.0, and 4.0.0, allows remote attackers to in... Read more
Affected Products : identity_manager_roles_based_provisioning_module identity_manager_user_application- Published: Oct. 08, 2011
- Modified: Apr. 11, 2025