Latest CVE Feed
-
4.3
MEDIUMCVE-2019-1010220
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: "ND_PRINT((ndo, "%s", buf));", in function named "print_prefix", in "print-hncp.c... Read more
Affected Products : tcpdump- Published: Jul. 22, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4102
Cross-site scripting (XSS) vulnerability in search.php for sBlog 0.7.3 Beta allows remote attackers to inject arbitrary HTML and web script via a leading '"/></> sequence in the search string.... Read more
Affected Products : sblog- Published: Jul. 31, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4079
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft SMS Text Messaging Enterprise allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) q parameter to (a) admin/membersearch.php, or (3) the userid parameter ... Read more
Affected Products : sms_text_messaging_enterprise- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-1110
An issue has been discovered in GitLab CE/EE affecting all versions from 18.0 before 18.0.1. In certain circumstances, a user with limited permissions could access Job Data via a crafted GraphQL query.... Read more
Affected Products : gitlab- Published: May. 22, 2025
- Modified: May. 29, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2007-4088
Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) f, (3) quote, and (4) act parameters to cp.php; the (5) u parameter to user.php; the (6) f parameter... Read more
Affected Products : vikingboard- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4075
Cross-site scripting (XSS) vulnerability in index.asp in Alisveris Sitesi Scripti allows remote attackers to inject arbitrary web script or HTML via the q parameter in a search mod action. NOTE: the provenance of this information is unknown; the details ... Read more
Affected Products : alisveris_sitesi_script- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-0516
Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.... Read more
Affected Products : gitlab- Published: Feb. 12, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2007-4081
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to inject arbitrary web script or HTML via vectors in (a) merchants/index.php, including the (1) id or (2) msg parameter in a programedit action... Read more
Affected Products : affiliate_network_pro- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4089
Vikingboard 0.1.2 allows remote attackers to obtain sensitive information via the debug parameter to (1) forum.php, (2) cp.php, and possibly other unspecified components.... Read more
Affected Products : vikingboard- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2019-12903
Pydio Cells before 1.5.0, when supplied with a Name field in an unexpected Unicode format, fails to handle this and includes the database column/table name as pert of the error message, exposing sensitive information.... Read more
Affected Products : cells- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4058
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll 2.2.5.42958 in EMC VMware 6.0.0 allows remote attackers to execute arbitrary local programs via a full pathname in the first argument to the StartProcess method.... Read more
Affected Products : vmware- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2023-2467
Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)... Read more
- Published: May. 03, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-4064
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.2, and 4.7.x before 4.7.7, (1) allow remote attackers to inject arbitrary web script or HTML via "some server variables," including PHP_SELF; and (2) allow remote authenticated adm... Read more
Affected Products : drupal- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4048
Cross-site scripting (XSS) vulnerability in index.php in phpSysInfo 2.5.4-dev and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : phpsysinfo- Published: Jul. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2016-3723
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.... Read more
- Published: May. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-3727
The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.... Read more
- Published: May. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-4037
Guidance Software EnCase allows user-assisted attackers to trigger a buffer over-read and application crash via a malformed NTFS filesystem containing a modified FILE record with a certain large offset. NOTE: the vendor disputes the significance of this i... Read more
Affected Products : encase- Published: Jul. 27, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4066
Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, a... Read more
Affected Products : libvorbis- Published: Sep. 21, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4020
Multiple cross-site scripting (XSS) vulnerabilities in login.php in AdMan 1.0.20051202 FF 3 patch and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pwd parameters.... Read more
Affected Products : adman- Published: Jul. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-4021
Multiple cross-site scripting (XSS) vulnerabilities in login.php in Brain Book Software Secure 1.0.20070629 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pwd parameters.... Read more
Affected Products : software_secure- Published: Jul. 26, 2007
- Modified: Apr. 09, 2025