Latest CVE Feed
-
4.3
MEDIUMCVE-2015-3793
CFPreferences in Apple iOS before 8.4.1 allows attackers to bypass the third-party app-sandbox protection mechanism and read arbitrary managed preferences via a crafted app.... Read more
Affected Products : iphone_os- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3908
Ansible before 1.9.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid ce... Read more
Affected Products : ansible- Published: Aug. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3983
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. NOTE: this issue was SPLI... Read more
Affected Products : pacemaker_configuration_system- Published: May. 14, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-5881
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.... Read more
Affected Products : yui- Published: Nov. 16, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2018-8425
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.... Read more
- Published: Sep. 13, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2012-5669
The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to BDF fonts and an incorrect calculation that triggers an out-of-boun... Read more
Affected Products : freetype- Published: Jan. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2019-1172
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerabilit... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_1507 windows_10_1803 +3 more products- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-4796
Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).... Read more
Affected Products : snitz_forums_2000- Published: Sep. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2018-8452
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsof... Read more
- Published: Sep. 13, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2006-2143
Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags.... Read more
Affected Products : textfilebb- Published: May. 02, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-0590
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a drag-and-drop operation.... Read more
Affected Products : iphone_os- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-0588
Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0586, CVE-2012-0587, and CVE-2012-0589.... Read more
Affected Products : iphone_os- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-2933
Cross-site scripting (XSS) vulnerability in the Html class in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a LanguageConverter substitution string when using a la... Read more
Affected Products : mediawiki- Published: Apr. 13, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2012-0471
Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script... Read more
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-2282
Cross-site scripting (XSS) vulnerability in X7 Chat 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the URL of an avatar, possibly related to the avatar parameter in register.php.... Read more
Affected Products : x7_chat- Published: May. 10, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2023-39343
Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 security Sys... Read more
Affected Products : sulu- Published: Aug. 04, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-41802
Missing Authorization vulnerability in Team Heateor Super Socializer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Socializer: from n/a through 7.13.54.... Read more
Affected Products : super_socializer- Published: Dec. 13, 2024
- Modified: Jun. 05, 2025
-
4.3
MEDIUMCVE-2012-0059
Spacewalk-backend in Red Hat Network (RHN) Satellite and Proxy 5.4 includes cleartext user passwords in an error message when a system registration XML-RPC call fails, which allows remote administrators to obtain the password by reading (1) the server log... Read more
- Published: Feb. 05, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-5277
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.... Read more
- Published: Dec. 09, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-1819
Google Chrome before 12.0.742.91 allows remote attackers to perform unspecified injection into a chrome:// page via vectors related to extensions.... Read more
Affected Products : chrome- Published: Jun. 09, 2011
- Modified: Apr. 11, 2025