Latest CVE Feed
-
4.3
MEDIUMCVE-2009-3698
An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of service (system process restart) via a crafted application, possibly a related issue to CVE-2009-2656.... Read more
Affected Products : android- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3601
Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject arbitrary web script or HTML via the clr parameter in a vote action.... Read more
Affected Products : ultimate_poll- Published: Oct. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3599
Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitrary web script or HTML via the bid_id parameter.... Read more
Affected Products : hubscript- Published: Oct. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-3592
Cross-site scripting (XSS) vulnerability in customer/home.php in Qualiteam X-Cart allows remote attackers to inject arbitrary web script or HTML via the email parameter in a subscribed action, a different vector than CVE-2005-1823.... Read more
Affected Products : x-cart- Published: Oct. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2010-2763
The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to by... Read more
- Published: Sep. 09, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2778
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 7.x before 7.0 post-SP4 FTF and 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to a "Javascript XSS exploit."... Read more
Affected Products : groupwise- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-0162
Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.... Read more
- Published: May. 13, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0072
Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.... Read more
Affected Products : internet_explorer- Published: Jan. 08, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0057
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP sess... Read more
Affected Products : unified_communications_manager- Published: Jan. 22, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0166
The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.... Read more
- Published: Apr. 23, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0054
PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers t... Read more
- Published: Jan. 16, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2009-0053
PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers t... Read more
- Published: Jan. 16, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7281
Open Ticket Request System (OTRS) before 2.2.7 sends e-mail containing a Bcc header field that lists the Blind Carbon Copy recipients, which allows remote attackers to obtain potentially sensitive e-mail address information by reading this field.... Read more
Affected Products : otrs- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-7266
Cross-site scripting (XSS) vulnerability in an unspecified Shockwave Flash file in RSA Adaptive Authentication 2.x and 5.7.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : adaptive_authentication- Published: Nov. 26, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-7271
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/... Read more
Affected Products : eclipse_ide- Published: Jan. 13, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2010-2779
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."... Read more
Affected Products : groupwise- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-7236
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 and 10.1.3.1 allows remote attackers to affect integrity via unknown vectors, aka AS05.... Read more
Affected Products : application_server- Published: Sep. 14, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7253
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) atta... Read more
Affected Products : lotus_domino_server- Published: Jan. 25, 2010
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2008-7206
Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS).... Read more
Affected Products : elog_web_logbook- Published: Sep. 11, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-7257
CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary HTTP headers as demonstrated by a redirect attack involvi... Read more
- Published: Jun. 29, 2010
- Modified: Apr. 11, 2025