Latest CVE Feed
-
4.3
MEDIUMCVE-2013-1714
The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote at... Read more
- Published: Aug. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3562
Unspecified vulnerability in the Portal component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : fusion_middleware- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-3513
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity, related to HTML Pages.... Read more
Affected Products : e-business_suite- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1718
The Web Agents component in CA SiteMinder R6 before SP6 CR2 and R12 before SP3 CR2 does not properly handle multi-line headers, which allows remote authenticated users to conduct impersonation attacks and gain privileges via crafted data.... Read more
- Published: Apr. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1723
Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to projects/hg-helloworld/news/. NOTE: some of these details are obta... Read more
Affected Products : redmine- Published: Apr. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1689
Multiple cross-site scripting (XSS) vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Apr. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2004-0804
Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.... Read more
Affected Products : libtiff- Published: Nov. 03, 2004
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-0799
Moodle 2.0.x before 2.0.7 and 2.1.x before 2.1.4, when an anonymous front-page forum is enabled, allows remote attackers to obtain session keys for their sessions by visiting the front page.... Read more
Affected Products : moodle- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0782
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/setup-config.php in the installation component in WordPress 3.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dbhost, (2) dbname, or (3) uname parame... Read more
Affected Products : wordpress- Published: Jan. 30, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0765
Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories.... Read more
- Published: Feb. 15, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0850
The sbr_qmf_synthesis function in libavcodec/aacsbr.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (application crash) via a crafted mpg file that triggers memory corruption involving the v_off variable, probably a buffer un... Read more
Affected Products : ffmpeg- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0849
Integer overflow in the ff_j2k_dwt_init function in libavcodec/j2k_dwt.c in FFmpeg before 0.9.1 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted JPEG2000 image that triggers an incorrect check f... Read more
Affected Products : ffmpeg- Published: Aug. 27, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2024-20434
A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane of an affected device. This vulnerability is due to improper handling of frames with VLAN tag i... Read more
Affected Products : ios_xe- Published: Sep. 25, 2024
- Modified: Oct. 08, 2024
-
4.3
MEDIUMCVE-2012-0834
Cross-site scripting (XSS) vulnerability in lib/QueryRender.php in phpLDAPadmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the base parameter in a query_engine action to cmd.php.... Read more
- Published: Feb. 11, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0873
Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode paramete... Read more
Affected Products : dolphin- Published: Feb. 23, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-0720
Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary web script or HTML via the search parameter to webmin_search.cgi (aka the search section), and possibly other compon... Read more
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-0862
IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.... Read more
- Published: Feb. 21, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2842
Apple Safari before 4.0.4 does not properly implement certain (1) Open Image and (2) Open Link menu options, which allows remote attackers to read local HTML files via a crafted web site.... Read more
Affected Products : safari- Published: Nov. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-31839
Cross-Site Request Forgery (CSRF) vulnerability in digireturn DN Footer Contacts allows Cross Site Request Forgery. This issue affects DN Footer Contacts: from n/a through 1.8.... Read more
Affected Products : footer_contacts_bar- Published: Apr. 01, 2025
- Modified: Apr. 01, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2008-0688
Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action.... Read more
Affected Products : domain_trader- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025