Latest CVE Feed
-
4.3
MEDIUMCVE-2002-1495
Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML via (1) attached file names in the Read Mail feature, (2) text/html mails that are displayed in a pop-up window, and (3) certain malicio... Read more
Affected Products : jawmail- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-4638
IBM Security Secret Server 10.7 does not set the secure attribute on authorization tokens or session cookies. This could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 170044.... Read more
Affected Products : security_secret_server- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3815
Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)3, 7.1 before 7.1(2)78, 7.2 before 7.2(4)16, 8.0 before 8.0(4)6, and 8.1 before 8.1(1)13, when configured as a VPN using Microso... Read more
- Published: Oct. 23, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2002-1493
Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script via (1) STYLE attributes or (2) SRC attributes in an IMG tag.... Read more
Affected Products : htmlgear_guestgear- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1497
Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response.... Read more
Affected Products : null_httpd- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-6222
A consistency issue was addressed with improved state handling. This issue is fixed in iOS 12.2. A website may be able to access the microphone without the microphone use indicator being shown.... Read more
Affected Products : iphone_os- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2008-3842
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demons... Read more
- Published: Aug. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2008-3740
Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : drupal- Published: Aug. 27, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2003-1561
Opera, probably before 7.50, sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.... Read more
Affected Products : opera- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2008-3779
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to inject arbitrary web script or HTML via the words parameter in a search action.... Read more
Affected Products : five_star_review_script- Published: Aug. 26, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2003-1438
Race condition in BEA WebLogic Server and Express 5.1 through 7.0.0.1, when using in-memory session replication or replicated stateful session beans, causes the same buffer to be provided to two users, which could allow one user to see session data that w... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-5243
There is a Clickjacking vulnerability in Huawei HG255s product. An attacker may trick user to click a link and affect the integrity of a device by exploiting this vulnerability.... Read more
- Published: Jun. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2019-4330
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 does not set the secure attribute for cookies in HTTPS sessions, which could cause the user agent to send those cookies in plaintext over an HTTP session. IBM X-Force ID: 161210.... Read more
Affected Products : security_guardium_big_data_intelligence- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2003-1539
Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.... Read more
Affected Products : simple_file_manager- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-1441
Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.... Read more
Affected Products : posadis- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2002-1455
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.... Read more
Affected Products : omnihttpd- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2003-0404
Multiple Cross Site Scripting (XSS) vulnerabilities in Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, allow remote attackers to insert arbitrary HTML and script via text variables, as demonstrated using the errInfo parameter of the default login ... Read more
- Published: Jun. 30, 2003
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2019-7284
This issue was addressed with improved checks. This issue is fixed in iOS 12.2. Processing a maliciously crafted mail message may lead to S/MIME signature spoofing.... Read more
Affected Products : iphone_os- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-3313
Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuo52582.... Read more
- Published: Jul. 09, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2003-1508
Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filename.... Read more
Affected Products : mirc- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025