Latest CVE Feed
-
3.5
LOWCVE-2012-3445
The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of service (libvirtd crash) via an RPC command with nparams set ... Read more
Affected Products : libvirt- Published: Aug. 07, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-4428
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to ... Read more
- Published: Oct. 27, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-2381
Unspecified vulnerability in Oracle MySQL 5.6.10 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server Privileges.... Read more
Affected Products : mysql- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-4349
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or ... Read more
Affected Products : phpmyadmin- Published: Jun. 25, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2012-5096
Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors.... Read more
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2019-1010310
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish users by putting code in reminder description. The impact is: Admins can phish any user or group of users for credentials / credit cards. The component is: Tool... Read more
Affected Products : glpi- Published: Jul. 12, 2019
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-3149
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.26 and earlier allows remote authenticated users to affect confidentiality, related to MySQL Client.... Read more
Affected Products : mysql- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-2289
res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authenticated users to cause a denial of service (crash) via a SUBSCRIBE request without any Accept headers, which triggers an invalid pointer... Read more
Affected Products : asterisk- Published: Apr. 18, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-4995
Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query that is not properly handled during the display of row in... Read more
Affected Products : phpmyadmin- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-4762
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.0 through 8.0.0.1 CF13 and 8.5.0 before CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_portal- Published: Sep. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-2287
channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote authe... Read more
- Published: Apr. 18, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2013-3811
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to InnoDB, a different vulnerability than CVE-2013-3806.... Read more
Affected Products : mysql- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2014-3102
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF28 and 8.0.0 before 8.0.0.1 CF13 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_portal- Published: Aug. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-3177
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sensitive information via a subscription request.... Read more
Affected Products : moodle- Published: Jun. 01, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2015-2269
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) alt o... Read more
Affected Products : moodle- Published: Jun. 01, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3594
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host a... Read more
- Published: Aug. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2024-39846
NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, data at rest is encrypted, but is decrypted within process memory during use.... Read more
Affected Products :- Published: Jun. 29, 2024
- Modified: Nov. 25, 2024
-
3.5
LOWCVE-2024-34713
sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. Prior to version 1.6.3, any user authorized to connect to a ssh server using `sshproxy` can inject options to the `ssh` command executed... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2022-45819
Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.... Read more
Affected Products : popup_maker- Published: Dec. 13, 2024
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2022-3624
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is recommended to app... Read more
Affected Products : linux_kernel- Published: Oct. 21, 2022
- Modified: Nov. 21, 2024