Latest CVE Feed
-
4.3
MEDIUMCVE-2013-1623
The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguish... Read more
Affected Products : cyassl- Published: Feb. 08, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1524
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Attachments.... Read more
Affected Products : e-business_suite- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3763
Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.... Read more
Affected Products : mantisbt- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 ... Read more
- Published: Mar. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1471
Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Ad... Read more
Affected Products : fortimail fortimail-2000b fortimail-200d fortimail-400c fortimail-5002b fortimail-vm2000- Published: Feb. 04, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1571
Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors ... Read more
- Published: Jun. 18, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2290
Cross-site scripting (XSS) vulnerability in the dashboard of the ArubaOS Administration WebUI in Aruba Networks ArubaOS 6.2.x before 6.2.0.3, 6.1.3.x before 6.1.3.7, 6.1.x-FIPS before 6.1.4.3-FIPS, and 6.1.x-AirGroup before 6.1.3.6-AirGroup, as used by Mo... Read more
Affected Products : arubaos- Published: Mar. 28, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2270
Cross-site scripting (XSS) vulnerability in the administration page in Airvana HubBub C1-600-RT and Sprint AIRAVE 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2010-3810
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly handle the History object, which allows remote attackers to spoof the location bar's URL or add URLs to the history via a c... Read more
- Published: Nov. 22, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4066
IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to conduct clickjacking attacks by creating an overlay interface on top of the Web Console interface.... Read more
Affected Products : infosphere_information_server- Published: Oct. 02, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1501
Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Login.... Read more
Affected Products : e-business_suite- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1490
Unspecified vulnerability in Oracle Java SE 7 Update 11 (JRE 1.7.0_11-b21) allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors, aka "Issue 51," a different vulnerability than CVE-2013-0431. NOTE: as of 201301... Read more
- Published: Jan. 31, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1742
Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1... Read more
Affected Products : bugzilla- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1671
Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.... Read more
Affected Products : firefox- Published: May. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2244
Multiple cross-site scripting (XSS) vulnerabilities in lib/conditionlib.php in Moodle 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allow remote attackers to inject arbitrary web script or HTML via the conditional access rule value of a user field.... Read more
Affected Products : moodle- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2768
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote atta... Read more
- Published: Sep. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2020-26034
An account-enumeration issue was discovered in Zammad before 3.4.1. The Create User functionality is implemented in a way that would enable an anonymous user to guess valid user email addresses. The application responds differently depending on whether th... Read more
Affected Products : zammad- Published: Dec. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-1540
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerabilit... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-2396
VideoLAN VLC media player 2.0.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted MP4 file.... Read more
Affected Products : vlc_media_player- Published: Apr. 19, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2179
X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) b... Read more
Affected Products : x_display_manager- Published: Dec. 27, 2013
- Modified: Apr. 11, 2025