Latest CVE Feed
-
4.3
MEDIUMCVE-2013-1055
The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks ... Read more
- Published: Apr. 07, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-8648
Microsoft Edge in Microsoft Windows Version 1703 allows an attacker to obtain information to further compromise the user's system, due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". Thi... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2013-1441
econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependent users to cause a denial of service (crash) via a crafted image file.... Read more
Affected Products : exactimage- Published: Sep. 16, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2016-3722
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."... Read more
- Published: May. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2007-3725
The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.... Read more
Affected Products : clamav- Published: Jul. 12, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-1456
Cross-site scripting (XSS) vulnerability in the login page in Open Web Analytics (OWA) before 1.5.6 allows remote attackers to inject arbitrary web script or HTML via the owa_user_id parameter to index.php.... Read more
Affected Products : open_web_analytics- Published: Mar. 01, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1014
Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.... Read more
- Published: May. 20, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1034
Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in Apple Mac OS X Server before 2.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : os_x_server- Published: Sep. 19, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1013
XSS Auditor in WebKit in Apple Safari before 6.0.5 does not properly rewrite URLs, which allows remote attackers to trigger unintended form submissions via unspecified vectors.... Read more
Affected Products : safari- Published: Jun. 05, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2012-3243
Cross-site scripting (XSS) vulnerability in the SEOgento plugin for Magento allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from thi... Read more
Affected Products : seogento- Published: May. 20, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-1445
The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive informati... Read more
Affected Products : pycrypto- Published: Oct. 26, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1466
Multiple cross-site scripting (XSS) vulnerabilities in glFusion before 1.2.2.pl4 allow remote attackers to inject arbitrary web script or HTML via the (1) subject parameter to profiles.php; (2) address1, (3) address2, (4) calendar_type, (5) city, (6) stat... Read more
Affected Products : glfusion- Published: Feb. 05, 2014
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2007-6520
Opera before 9.25 allows remote attackers to conduct cross-domain scripting attacks via unknown vectors related to plug-ins.... Read more
Affected Products : opera_browser- Published: Dec. 24, 2007
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2005-3973
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allow remote attackers to inject arbitrary web script or HTML via various HTML tags and values, such as the (1) legend tag and the value parameter us... Read more
Affected Products : drupal- Published: Dec. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-3232
Cross-site scripting (XSS) vulnerability in search.php in web@all 2.0, as downloaded before May 30, 2012, allows remote attackers to inject arbitrary web script or HTML via the _text[title] parameter.... Read more
Affected Products : web\@all- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-1524
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Attachments.... Read more
Affected Products : e-business_suite- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2013-0970
Messages in Apple Mac OS X before 10.8.3 allows remote attackers to bypass the FaceTime call-confirmation prompt via a crafted FaceTime: URL.... Read more
- Published: Mar. 15, 2013
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2006-4710
Multiple cross-site scripting (XSS) vulnerabilities in NewsGator FeedDemon before 2.0.0.25 allow remote attackers to inject arbitrary web script or HTML via an Atom 1.0 feed, as demonstrated by certain test cases of the James M. Snell Atom 1.0 feed reader... Read more
Affected Products : feeddemon- Published: Sep. 12, 2006
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2012-3293
Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1 allows remote attackers to inject arbitrary web s... Read more
Affected Products : websphere_application_server- Published: Aug. 21, 2012
- Modified: Apr. 11, 2025
-
4.3
MEDIUMCVE-2009-1524
Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.... Read more
Affected Products : jetty- Published: May. 05, 2009
- Modified: Apr. 09, 2025