Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3501
The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length.... Read more
Affected Products : clamav- Published: Nov. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-0971
Cross-site scripting (XSS) vulnerability in futomi's CGI Cafe Access Analyzer CGI Standard Version 3.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : access_analyzer_cgi- Published: Mar. 19, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-4871
Cross-site scripting (XSS) vulnerability in My Little Forum 1.75 and 2.0 Beta 23 allows remote attackers to inject arbitrary web script or HTML via BBcode IMG tags.... Read more
Affected Products : my_little_forum- Published: Nov. 01, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3416
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : e-business_suite- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6205
Cross-site scripting (XSS) vulnerability in seeurl.php in Xavier Flahaut URLStreet 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) language, (2) order, and (3) filter parameters. NOTE: the provenance of this information is ... Read more
Affected Products : urlstreet- Published: Feb. 20, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2696
Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary... Read more
- Published: Aug. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2005-3473
Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog 0.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entry, (2) blog_subject, and (3) blog_text parameters (involving the temp_subject variable) ... Read more
Affected Products : simple_php_blog- Published: Nov. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2009-2684
Multiple cross-site scripting (XSS) vulnerabilities in Jetdirect and the Embedded Web Server (EWS) on certain HP LaserJet and Color LaserJet printers, and HP Digital Senders, allow remote attackers to inject arbitrary web script or HTML via the (1) Produc... Read more
Affected Products : laserjet_2410 laserjet_2420 color_laserjet_4730_mfp laserjet_4240 laserjet_4345_mfp laserjet_9050_mfp laserjet_m3027_mfp laserjet_m3035_mfp laserjet_m5025_mfp laserjet_p4014 +25 more products- Published: Oct. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-2342
Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before 1.22 allows remote attackers to inject arbitrary web script or HTML via the username field.... Read more
Affected Products : cmme- Published: Jul. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-6915
Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote attackers to inject arbitrary web script or HTML via the propid parameter.... Read more
Affected Products : zeeproperty- Published: Aug. 07, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-4704
libavcodec/vorbis_dec.c in the Vorbis decoder in FFmpeg 0.6.1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted .ogg file, related to the vorbis_floor0_decode function. NOTE: this might overlap CVE-2011-04... Read more
Affected Products : ffmpeg- Published: Jan. 22, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3841
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the rev parameter to the view script or (2) the query string to the login script.... Read more
Affected Products : twiki- Published: Oct. 18, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3827
Apple iOS before 4.2 does not properly validate signatures before displaying a configuration profile in the configuration installation utility, which allows remote attackers to spoof profiles via unspecified vectors.... Read more
Affected Products : iphone_os- Published: Nov. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3831
Photos in Apple iOS before 4.2 enables support for HTTP Basic Authentication over an unencrypted connection, which allows man-in-the-middle attackers to read MobileMe account passwords by spoofing a MobileMe Gallery server during a "Send to MobileMe" acti... Read more
Affected Products : iphone_os- Published: Nov. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-5438
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors.... Read more
Affected Products : application_server- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-3018
RSA Access Manager Server 5.5.3 before 5.5.3.172, 6.0.4 before 6.0.4.53, and 6.1 before 6.1.2.01 does not properly perform cache updates, which allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : access_manager_server- Published: Sep. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3886
The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sen... Read more
Affected Products : internet_explorer- Published: Oct. 08, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3913
CRLF injection vulnerability in TransWARE Active! mail 6 build 6.40.010047750 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.... Read more
Affected Products : active\!_mail- Published: Nov. 05, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2985
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the searchTerm parameter to ServiceRegistry/HelpSearch.do or (2) the quer... Read more
Affected Products : websphere_service_registry_and_repository- Published: Aug. 10, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-3890
Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to inject arbitrary web script or HTML via the command parameter to the administration interface, as demonstrated by the command parameter to ES... Read more
Affected Products : omnifind- Published: Nov. 12, 2010
- Modified: Apr. 11, 2025