Latest CVE Feed
-
4.3
MEDIUMCVE-2011-1578
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html at the ... Read more
- Published: Apr. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-2567
The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response ... Read more
Affected Products : trojita- Published: Mar. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6919
Cross-site scripting (XSS) vulnerability in the googleSearch (CSE) (com_googlesearch_cse) component 3.0.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the q parameter to index.php.... Read more
Affected Products : googlesearch- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6744
Basware Banking (Maksuliikenne) before 8.90.07.X relies on the client to enforce (1) login verification, (2) audit trail creation, and (3) account locking, which allows remote attackers to "disrupt security-critical functions" by "dropping network traffic... Read more
Affected Products : banking- Published: Aug. 31, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6909
Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a tor... Read more
Affected Products : download_station- Published: Sep. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3432
Cross-site scripting (XSS) vulnerability in the management console in Symantec Data Insight 3.x and 4.x before 4.5 allows remote attackers to inject arbitrary web script or HTML via an unspecified form field.... Read more
Affected Products : data_insight- Published: Jun. 27, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3574
Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.... Read more
Affected Products : poi- Published: Sep. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0706
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenti... Read more
- Published: Feb. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-3271
Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-v... Read more
Affected Products : tomcat- Published: Oct. 13, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-3511
The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support ... Read more
Affected Products : openssl- Published: Aug. 13, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2017-7674
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisonin... Read more
Affected Products : tomcat- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2015-7576
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.... Read more
- Published: Feb. 16, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0509
Unspecified vulnerability in the Oracle Internet Expenses component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to AP Web Utilities.... Read more
Affected Products : e-business_suite- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-2379
Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.... Read more
Affected Products : squirrelmail- Published: Dec. 05, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2015-6165
Microsoft Silverlight 5 before 5.1.41105.00 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Silverlight Information Disclosure Vulnerability," a different vulnerability than CVE-2015-6114.... Read more
Affected Products : silverlight- Published: Dec. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6169
Microsoft Edge misparses HTTP responses, which allows remote attackers to redirect users to arbitrary web sites via unspecified vectors, aka "Microsoft Edge Spoofing Vulnerability."... Read more
Affected Products : edge- Published: Dec. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3629
XML external entity (XXE) vulnerability in the XML Exchange module in Apache Qpid 0.30 allows remote attackers to cause outgoing HTTP connections via a crafted message.... Read more
Affected Products : qpid- Published: Nov. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4020
RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record with a ... Read more
- Published: Aug. 25, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-2248
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247.... Read more
- Published: Jul. 08, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-8726
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how affected Microsoft scripting engines handle objects in memory, aka "Microsof... Read more
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025