Latest CVE Feed
-
4.3
MEDIUMCVE-2016-1625
The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers to bypass intended restrictions via unspecified vectors,... Read more
- Published: Feb. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-38174
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability... Read more
Affected Products : edge_chromium- Published: Dec. 07, 2023
- Modified: Jan. 01, 2025
-
4.3
MEDIUMCVE-2016-1614
The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensitive ... Read more
Affected Products : chrome- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-0829
Multiple array index errors in set.c in dvipng 1.11 and 1.12, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed DVI file.... Read more
- Published: May. 07, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-2380
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get conver... Read more
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2010-0892
Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2.0.00.27 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : database_server- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-0330
Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname).... Read more
Affected Products : gallery- Published: Jan. 21, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-7830
The pcapng_read_if_descr_block function in wiretap/pcapng.c in the pcapng parser in Wireshark 1.12.x before 1.12.8 uses too many levels of pointer indirection, which allows remote attackers to cause a denial of service (incorrect free and application cras... Read more
- Published: Nov. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-1899
Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2023-3964
An issue has been discovered in GitLab affecting all versions starting from 13.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for users to access composer packages on public p... Read more
Affected Products : gitlab- Published: Dec. 01, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2007-5796
Cross-site scripting (XSS) vulnerability in the management console in Blue Coat ProxySG before 4.2.6.1, and 5.x before 5.2.2.5, allows remote attackers to inject arbitrary web script or HTML by modifying the URL that is used for loading Certificate Revoca... Read more
- Published: Nov. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1190
thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private ... Read more
Affected Products : mediawiki- Published: Mar. 31, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-4903
Cross-site scripting (XSS) vulnerability in the leave comment (feedback) feature in Typo 5.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) comment[author] (Name) and (2) comment[url] (Website) parameters.... Read more
Affected Products : typo- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-1406
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTT... Read more
- Published: Jun. 11, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-7941
libxml2 2.9.2 does not properly stop parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and libxml2 crash) via crafted XML data to the (1) xmlParseEntityDecl or (2) xmlParseConditionalSections ... Read more
- Published: Nov. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-5798
Multiple cross-site scripting (XSS) vulnerabilities in uddigui/navigateTree.do in the UDDI user console in IBM WebSphere Application Server (WAS) before 6.1.0 Fix Pack 13 (6.1.0.13) allow remote attackers to inject arbitrary web script or HTML via the (1)... Read more
Affected Products : websphere_application_server- Published: Nov. 03, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2024-47401
Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1 and 9.5.x <= 9.5.9 fail to prevent detailed error messages from being displayed in Playbooks which allows an attacker to generate a large response and cause an amplified GraphQL response which in turn... Read more
- Published: Oct. 29, 2024
- Modified: Oct. 29, 2024
-
4.3
MEDIUMCVE-2007-6460
Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy Server before 0.101 allow remote attackers to inject arbitrary web script or HTML via the URI, which is later displayed by (1) log.php or (2) logerror.php, a different vulnerability than CV... Read more
Affected Products : anon_proxy_server- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3622
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message that reaches a mailing-list archive, aka "persistent JavaScript injection."... Read more
- Published: Sep. 16, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-4428
Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter.... Read more
Affected Products : cerberus_helpdesk- Published: Dec. 20, 2005
- Modified: Apr. 03, 2025