Latest CVE Feed
-
4.3
MEDIUMCVE-2015-7708
Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat_description parameter in an updatecat action to admin/categories.php.... Read more
Affected Products : 4images- Published: Oct. 05, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8253
The Frontel protocol before 3 on RSI Video Technologies Videofied devices sets up AES encryption but sends all traffic in cleartext, which allows remote attackers to obtain sensitive (1) message or (2) MJPEG video data by sniffing the network.... Read more
Affected Products : frontel_protocol- Published: Dec. 27, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5920
The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors.... Read more
Affected Products : itunes- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5921
WebKit in Apple iOS before 9 mishandles "Content-Disposition: attachment" HTTP headers, which might allow man-in-the-middle attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : iphone_os- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8020
Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure.... Read more
Affected Products : clustered_data_ontap- Published: Jan. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2011-1578
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.3, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .html at the ... Read more
- Published: Apr. 27, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2011-0881
Unspecified vulnerability in the EMCTL component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7, and Oracle Enterprise Manager Grid Control 10.1.0.6, allows remote attackers to affect integrity via unknown vectors.... Read more
- Published: Jul. 20, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-3690
The DiskImages subsystem in Apple iOS before 8.4 and OS X before 10.10.4 allows attackers to obtain sensitive memory-layout information for the kernel via a crafted app.... Read more
- Published: Jul. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2006-1729
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file uplo... Read more
- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-8488
Cybozu Office 10.3.0 allows remote attackers to read image files via a crafted e-mail message, a different vulnerability than CVE-2015-8487.... Read more
Affected Products : office- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7677
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEit... Read more
Affected Products : moveit_dmz- Published: Feb. 10, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-5593
The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attac... Read more
- Published: Oct. 30, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-8309
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."... Read more
Affected Products : cherrymusic- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2006-1392
Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in the login server in University of Washington Pubcookie 3.0.0, 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unsp... Read more
Affected Products : pubcookie- Published: Mar. 26, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2015-7900
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote attackers to obtain sensitive debugging information by entering a crafted URL to trigger an exception, and then visiting a certain status page.... Read more
Affected Products : mango_automation- Published: Oct. 28, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2020-9707
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Aug. 19, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5894
The X.509 certificate-trust implementation in Apple OS X before 10.11 does not recognize that the kSecRevocationRequirePositiveResponse flag implies a revocation-checking requirement, which makes it easier for man-in-the-middle attackers to spoof endpoint... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-3821
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.... Read more
Affected Products : ios- Published: Jan. 16, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2013-5780
Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confident... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2015-7886
NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.... Read more
- Published: Jan. 18, 2016
- Modified: Apr. 12, 2025