Latest CVE Feed
-
4.3
MEDIUMCVE-2012-3413
The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attackers to inject arbitrary web script or HTML via a crafted email.... Read more
Affected Products : kde_pim- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-2862
The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to bypass intended access restrictions via crafted requests, aka Bug IDs CSCsx07114, CSCsu70214, CS... Read more
Affected Products : ios- Published: Sep. 28, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5683
Multiple cross-site scripting (XSS) vulnerabilities in TikiWiki 1.9.8.1 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to the password reminder page (tiki-remind_password.php), (2) IMG tags in wiki... Read more
Affected Products : tikiwiki_cms\/groupware- Published: Oct. 26, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2022-0746
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.... Read more
Affected Products : dolibarr_erp\/crm- Published: Feb. 25, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-14628
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.... Read more
- Published: Jan. 17, 2023
- Modified: Jan. 22, 2025
-
4.3
MEDIUMCVE-2011-1819
Google Chrome before 12.0.742.91 allows remote attackers to perform unspecified injection into a chrome:// page via vectors related to extensions.... Read more
Affected Products : chrome- Published: Jun. 09, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-11802
In Apache Solr, the cluster can be partitioned into multiple collections and only a subset of nodes actually host any given collection. However, if a node receives a request for a collection it does not host, it proxies the request to a relevant node and ... Read more
Affected Products : solr- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-2947
Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages.... Read more
Affected Products : omega- Published: Sep. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2025-46708
Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.... Read more
Affected Products : ddk- Published: Jun. 27, 2025
- Modified: Jul. 01, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2008-3567
Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.... Read more
Affected Products : winamp- Published: Aug. 10, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2002-1803
Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag.... Read more
Affected Products : php-nuke- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-1992
The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to read content from a different (1) domain or (2) zone via a "trial and error" attack, aka "XSS Filter Information Disclosure Vulnerability."... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_server_2003 windows_vista windows_xp- Published: Dec. 14, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-1978
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4 does not properly validate the System.Net.Sockets trust level, which allows remote attackers to obtain sensitive information or trigger arbitrary outbound network traffic via (1) a crafted XAML browser applic... Read more
Affected Products : windows_7 windows_server_2008 .net_framework windows_2003_server windows_server_2003 windows_vista windows_xp- Published: Aug. 10, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-14853
A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip)... Read more
- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-3013
Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location head... Read more
Affected Products : opera_browser- Published: Aug. 31, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-5854
Launch Services in Apple Mac OS X 10.4.11 and 10.5.1 does not treat HTML files as unsafe content, which allows attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via a crafted HTML file.... Read more
Affected Products : mac_os_x- Published: Dec. 19, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2002-2115
Cross-site scripting (XSS) vulnerability in Hyper NIKKI System (HNS) Lite before 0.9 and HNS before 2.10-pl2 allows remote attackers to inject arbitrary web script or HTML.... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2011-1940
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.3.x before 3.3.10.1 and 3.4.x before 3.4.1 allow remote attackers to inject arbitrary web script or HTML via a crafted table name that triggers improper HTML rendering on a Tracking page,... Read more
Affected Products : phpmyadmin- Published: Jan. 26, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2023-45289
When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not forward sensitive headers such as "Authorization" or "Cookie". For example, a redirect from foo.com to www.foo.com wil... Read more
Affected Products : go- Published: Mar. 05, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2001-1522
Cross-site scripting (XSS) vulnerability in im.php in IMessenger for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via a message.... Read more
Affected Products : php-nuke- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025