Latest CVE Feed
-
4.3
MEDIUMCVE-2015-5341
mod_scorm in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 mishandles availability dates, which allows remote authenticated users to bypass intended access restrictions and read SCORM contents via unspecified vecto... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5355
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post-content or (2) post-title parameter to admin/edit.php.... Read more
- Published: Jul. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5352
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions vi... Read more
Affected Products : openssh- Published: Aug. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4637
The REST API in F5 BIG-IQ Cloud, Device, and Security 4.4.0 and 4.5.0 before HF2 and ADC 4.5.0 before HF2, when configured for LDAP remote authentication and the LDAP server allows anonymous BIND operations, allows remote attackers to obtain an authentica... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4476
Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.... Read more
- Published: Sep. 24, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5375
Cross-site scripting (XSS) vulnerability in unspecified dialogs for printing content in the Front End in Open-Xchange Server 6 and OX App Suite before 6.22.8-rev8, 6.22.9 before 6.22.9-rev15m, 7.x before 7.6.1-rev25, and 7.6.2 before 7.6.2-rev20 allows re... Read more
- Published: Sep. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-1030
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To explo... Read more
- Published: Aug. 14, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5441
Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Nov. 12, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3429
Cross-site scripting (XSS) vulnerability in example.html in Genericons before 3.3.1, as used in WordPress before 4.2.2, allows remote attackers to inject arbitrary web script or HTML via a fragment identifier.... Read more
- Published: Jun. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5444
Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : smart_profile_server_data_analytics_layer- Published: Oct. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-3660
Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.... Read more
Affected Products : safari- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0976
Cross-site scripting (XSS) vulnerability in Inductive Automation Ignition 7.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : ignition- Published: Apr. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-4458
The TLS implementation in the Cavium cryptographic-module firmware, as distributed with Cisco Adaptive Security Appliance (ASA) Software 9.1(5.21) and other products, does not verify the MAC field, which allows man-in-the-middle attackers to spoof TLS con... Read more
- Published: Jul. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-0823
IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.... Read more
Affected Products : websphere_application_server- Published: May. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5454
Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title parameter when adding a new item.... Read more
Affected Products : nucleus_cms- Published: Jul. 08, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2009-2713
The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive ... Read more
- Published: Aug. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-2904
Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.0 through 6.3, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly a related issue to CVE-2006-5653... Read more
Affected Products : java_system_messaging_server- Published: May. 30, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-4536
Multiple cross-site scripting (XSS) vulnerabilities in KSES, as used in WordPress before 3.0.4, allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the & (ampersand) character, (2) the case of an attribute name, (3) a ... Read more
Affected Products : wordpress- Published: Jan. 03, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-6088
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."... Read more
- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-2370
Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote attackers to affect integrity, related to BPM.... Read more
Affected Products : fusion_middleware- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025