Latest CVE Feed
-
3.5
LOWCVE-2010-3089
Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.... Read more
Affected Products : mailman- Published: Sep. 15, 2010
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-6147
Cross-site scripting (XSS) vulnerability in the tree render API (TCA-Tree) in the Backend API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via un... Read more
Affected Products : typo3- Published: Jul. 01, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5529
TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.... Read more
- Published: Nov. 20, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-2206
The Web Gateway component in IBM WebSphere MQ File Transfer Edition 7.0.4 and earlier allows remote authenticated users to read files of arbitrary users via vectors involving a username in a URI, as demonstrated by a modified metadata=fteSamplesUser field... Read more
Affected Products : websphere_mq- Published: Aug. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2024-23557
HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack. ... Read more
Affected Products : connections- Published: Apr. 18, 2024
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2012-6148
Cross-site scripting (XSS) vulnerability in the function menu API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : typo3- Published: Jul. 01, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-2101
Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (CPU and hard drive consumption) via a network request tha... Read more
Affected Products : nova- Published: Jun. 07, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-2214
proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (application crash) via a sequence of XMPP file-transfer requests... Read more
Affected Products : pidgin- Published: Jul. 03, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2007-5461
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request th... Read more
Affected Products : tomcat- Published: Oct. 15, 2007
- Modified: Apr. 09, 2025
-
3.5
LOWCVE-2020-11044
In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.... Read more
- Published: May. 07, 2020
- Modified: Nov. 21, 2024
-
3.5
LOWCVE-2013-0177
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web sc... Read more
- Published: Jan. 30, 2014
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-0172
Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which allows remote authenticated users to bypass intended restrictions on modifyi... Read more
Affected Products : samba- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-0297
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) site_name or (2) site_url parameter to apps/external/ajax/set... Read more
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2011-0904
The rfbSendFramebufferUpdate function in server/libvncserver/rfbserver.c in vino-server in Vino 2.x before 2.28.3, 2.32.x before 2.32.2, 3.0.x before 3.0.2, and 3.1.x before 3.1.1, when raw encoding is used, allows remote authenticated users to cause a de... Read more
Affected Products : vino- Published: May. 10, 2011
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5339
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 3.5.x before 3.5.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted name of (1) an event, (2) a procedure, or (3) a trigger.... Read more
Affected Products : phpmyadmin- Published: Oct. 25, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-0672
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified data.... Read more
Affected Products : wincc_tia_portal- Published: Mar. 21, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5064
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Software 10.0.0, 10.0.2, 10.1.0, 10.2.0, 10.2.2, 10.3.0, 10.5.0, and 11.0.0 through 11.2.0 allows remote authenticated users to affect confidentialit... Read more
Affected Products : financial_services_software- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-4836
Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that ... Read more
Affected Products : cognos_business_intelligence- Published: Mar. 05, 2013
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2012-5539
The Organic Groups (OG) module 7.x-1.x before 7.x-1.5 for Drupal does not properly maintain pending group memberships, which allows remote authenticated users to post to arbitrary groups by modifying their own account while a pending membership is waiting... Read more
- Published: Dec. 03, 2012
- Modified: Apr. 11, 2025
-
3.5
LOWCVE-2013-1244
Cross-site scripting (XSS) vulnerability in the portal module in Cisco WebEx Social allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL in the link field in a post, aka Bug ID CSCue67199.... Read more
Affected Products : webex_social- Published: May. 16, 2013
- Modified: Apr. 11, 2025