Latest CVE Feed
-
4.3
MEDIUMCVE-2007-3386
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to... Read more
Affected Products : tomcat- Published: Aug. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2011-2849
The WebSockets implementation in Google Chrome before 14.0.835.163 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.... Read more
Affected Products : chrome- Published: Sep. 19, 2011
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-3227
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.... Read more
Affected Products : rails- Published: Jun. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2007-3385
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote att... Read more
Affected Products : tomcat- Published: Aug. 14, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2021-21743
ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP response header information through a specially crafted HTTP request.... Read more
- Published: Oct. 20, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-1155
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to another user's reports using a specially crafted HTTP request. IBM Reference #: 1999754.... Read more
Affected Products : algo_one- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-3059
Cross-site scripting (XSS) vulnerability in the Voting plugin in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : joomla\!- Published: May. 03, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-4934
The netmon_open function in wiretap/netmon.c in the Netmon file parser in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not initialize certain structure members, which allows remote attackers to cause a denial of service (application crash) v... Read more
Affected Products : wireshark- Published: Jul. 30, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-21662
A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials ID of credentials stored in Jenkins.... Read more
Affected Products : xebialabs_xl_deploy- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2009-1789
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists b... Read more
- Published: May. 26, 2009
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2017-1107
IBM Marketing Platform 9.1.0, 9.1.2, 10.0, and 10.1 exposes sensitive information in the headers that could be used by an authenticated attacker in further attacks against the system. IBM X-Force ID: 120906.... Read more
Affected Products : marketing_platform- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2002-1636
Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for Oracle 9i Application Server (9iAS) allows remote attackers to inject arbitrary web script or HTML via the cbuf parameter to htp.print.... Read more
Affected Products : application_server- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2013-4589
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.... Read more
- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2021-21641
A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.... Read more
Affected Products : promoted_builds- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-5190
Smart Card Services in Apple Mac OS X before 10.9 does not properly implement certificate-revocation checks, which allows remote attackers to cause a denial of service (Smart Card usage outage) by interfering with the revocation-check procedure.... Read more
- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2017-1171
The IBM TRIRIGA Application Platform 3.3, 3,4, and 3,5 contain a vulnerability that could allow an authenticated user to execute Application actions they do not have access to. IBM Reference #: 2001083.... Read more
Affected Products : tririga_application_platform- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1119
IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow a remote attacker to obtain sensitive information. An attacker could send a specially-crafted request to cause an error message to be returned containing the full root path. An attacker could use... Read more
Affected Products : marketing_operations- Published: Nov. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4520
xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue is due to an incomplete fix for CVE-... Read more
Affected Products : libxslt- Published: Dec. 14, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-2073
Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate.... Read more
Affected Products : transifex- Published: May. 02, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2021-21654
Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.... Read more
Affected Products : p4- Published: May. 11, 2021
- Modified: Nov. 21, 2024