Latest CVE Feed
-
4.3
MEDIUMCVE-2012-5757
Cross-site scripting (XSS) vulnerability in the Web Client in IBM Rational ClearQuest 7.1.x before 7.1.2.10 and 8.x before 8.0.0.6 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : rational_clearquest- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5744
Multiple cross-site scripting (XSS) vulnerabilities in the guest portal in Cisco Identity Services Engine (ISE) Software allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCud11139 and CSCug02904.... Read more
Affected Products : identity_services_engine_software- Published: Aug. 30, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5702
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) com... Read more
Affected Products : dotproject- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5665
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.... Read more
- Published: Jan. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6853
Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored ... Read more
- Published: Jan. 26, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-27772
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned int`. This would most likely lead to an imp... Read more
- Published: Dec. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5672
Microsoft Excel Viewer (aka Xlview.exe) and Excel in Microsoft Office 2007 (aka Office 12) allow remote attackers to cause a denial of service (read access violation and application crash) via a crafted spreadsheet file, as demonstrated by a .xls file wit... Read more
- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5666
Cross-site scripting (XSS) vulnerability in bookmarks/js/bookmarks.js in ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to apps/bookmark/index.php.... Read more
- Published: Jan. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1904
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default ac... Read more
- Published: Mar. 20, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-29445
Affected versions of Confluence Server before 7.4.8, and versions from 7.5.0 before 7.11.0 allow attackers to identify internal hosts and ports via a blind server-side request forgery vulnerability in Team Calendars parameters.... Read more
Affected Products : confluence_server- Published: May. 07, 2021
- Modified: Feb. 12, 2025
-
4.3
MEDIUMCVE-2012-5625
OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating for instances, which allows attackers to obtain sensitive information by readi... Read more
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5606
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.9 and 4.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) file name to apps/files_versions/js/versions.js or (2) apps/files/js/filelist.js; or (3) event... Read more
- Published: Dec. 18, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0047
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.2 allows remote attackers to inject arbitrary web script or HTML via crafted Cascading Style Sheets (CSS) comments, aka "CSS injection vulnerability."... Read more
Affected Products : mediawiki- Published: Feb. 04, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-5591
Cross-site scripting (XSS) vulnerability in the Zero Point module 6.x-1.x before 6.x-1.18 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the path aliases.... Read more
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5023
The ActiveX controls in the HelpAsst component in NI Help Links in National Instruments LabWindows/CVI 2012 SP1 and earlier, LabVIEW 2012 SP1 and earlier, and other products allow remote attackers to cause a denial of service by triggering the display of ... Read more
- Published: Aug. 06, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5013
Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote attackers to inject arbitrary web script or HTML via (1) vectors involving PHP scripts and (2) unspecified ot... Read more
Affected Products : web_gateway- Published: Feb. 11, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5054
Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."... Read more
- Published: Dec. 11, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-5005
Multiple cross-site scripting (XSS) vulnerabilities in ajaxRequest/methodCall.do in Tripwire Enterprise 8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) m_target_class_name, (2) m_target_method_name, or (3) m_reque... Read more
Affected Products : tripwire_enterprise- Published: Jan. 29, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4996
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a crafted database name, (2) a crafted user name, (3) a... Read more
Affected Products : phpmyadmin- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4950
Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 parameter.... Read more
- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025