Latest CVE Feed
-
4.3
MEDIUMCVE-2013-6267
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.11.9 allow remote attackers to inject arbitrary web script or HTML via the (1) box parameter to messaging/messagebox.php, cidToEdit parameter to (2) adminregisteruser.php or (3) adm... Read more
Affected Products : claroline- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6325
IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote attackers to cause a denial of service (resource consumption) via a crafted request to a web services endpoint.... Read more
Affected Products : websphere_application_server- Published: Jan. 16, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6305
IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by leve... Read more
Affected Products : platform_symphony- Published: Jan. 21, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6315
IBM InfoSphere Enterprise Records 4.5.1 before 4.5.1.7-IER-IF001 and Enterprise Records 5.1.1 before 5.1.1.1-IER-IF003 do not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted... Read more
- Published: Mar. 06, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-27751
A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long` as well as a shif... Read more
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6337
Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet.... Read more
Affected Products : wireshark- Published: Nov. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6340
epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the amount of remaining data, which allows remote attackers to cause a denial of service (application crash) via a craf... Read more
Affected Products : wireshark- Published: Nov. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6327
Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1 and 1.4 before 1.4.0.0 iFix 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cr... Read more
Affected Products : sterling_connect_enterprise_http_option- Published: Dec. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6388
Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.... Read more
Affected Products : drupal- Published: Dec. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-6454
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via a -o-link attribute.... Read more
Affected Products : mediawiki- Published: May. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-6395
Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.... Read more
Affected Products : ganglia-web- Published: Dec. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-27758
A flaw was found in ImageMagick in coders/txt.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long`. This would most likely lead to ... Read more
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-27755
in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size. The patch resets the depth to a ... Read more
Affected Products : imagemagick- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6415
Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the uni... Read more
- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-27757
A floating point math calculation in ScaleAnyToQuantum() of /MagickCore/quantum-private.h could lead to undefined behavior in the form of a value outside the range of type unsigned long long. The flaw could be triggered by a crafted input file under certa... Read more
- Published: Dec. 08, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-0730
Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) language parameter to application/modules/admin/controllers/LanguagesController.p... Read more
Affected Products : newscoop- Published: Feb. 22, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2014-1820
Cross-site scripting (XSS) vulnerability in Master Data Services (MDS) in Microsoft SQL Server 2012 SP1 and 2014 on 64-bit platforms allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "SQL Master Data Services XSS Vulner... Read more
- Published: Aug. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-27761
WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outside the range of representable type `unsigned long` undefined behavior when a crafted input file was processed by ImageMagick. The patch ... Read more
- Published: Dec. 03, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-27767
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types `float` and `unsigned char`. This would most... Read more
- Published: Dec. 04, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-6836
Heap-based buffer overflow in the ms_escher_get_data function in plugins/excel/ms-escher.c in GNOME Office Gnumeric before 1.12.9 allows remote attackers to cause a denial of service (crash) via a crafted xls file with a crafted length value.... Read more
Affected Products : gnumeric- Published: Dec. 19, 2013
- Modified: Apr. 11, 2025