VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2020-15676MedOct 1, 2020
    risk 0.40cvss 6.1epss 0.02

    Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and…

  • CVE-2020-25626MedSep 30, 2020
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject…

  • CVE-2019-14904HigAug 26, 2020
    risk 0.40cvss 7.3epss 0.00

    A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw…

  • CVE-2020-6535MedJul 22, 2020
    risk 0.40cvss 6.1epss 0.01

    Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.

  • CVE-2020-6470MedMay 21, 2020
    risk 0.40cvss 6.1epss 0.01

    Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.

  • CVE-2020-12137MedApr 24, 2020
    risk 0.40cvss 6.1epss 0.02

    GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform…

  • CVE-2020-8647MedFeb 6, 2020
    risk 0.40cvss 6.1epss 0.00

    There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.

  • CVE-2020-7106MedJan 16, 2020
    risk 0.40cvss 6.1epss 0.02

    Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is…

  • CVE-2019-17022MedJan 8, 2020
    risk 0.40cvss 6.1epss 0.02

    When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage;…

  • CVE-2019-17016MedJan 8, 2020
    risk 0.40cvss 6.1epss 0.02

    When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and…

  • CVE-2014-4913MedDec 15, 2019
    risk 0.40cvss 6.1epss 0.01

    ZF2014-03 has a potential cross site scripting vector in multiple view helpers

  • CVE-2013-4158MedDec 11, 2019
    risk 0.40cvss 6.1epss 0.01

    smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)

  • CVE-2019-19709MedDec 11, 2019
    risk 0.40cvss 6.1epss 0.02

    MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.

  • CVE-2012-1115MedDec 5, 2019
    risk 0.40cvss 6.1epss 0.02

    A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.

  • CVE-2012-1114MedDec 5, 2019
    risk 0.40cvss 6.1epss 0.02

    A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.

  • CVE-2012-0812MedNov 22, 2019
    risk 0.40cvss 6.1epss 0.01

    PostfixAdmin 2.3.4 has multiple XSS vulnerabilities

  • CVE-2011-0544MedNov 14, 2019
    risk 0.40cvss 6.1epss 0.01

    phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.

  • CVE-2009-5046MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.02

    JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

  • CVE-2009-5049MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.02

    WebApp JSP Snoop page XSS in jetty though 6.1.21.

  • CVE-2010-2471MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.01

    Drupal versions 5.x and 6.x has open redirection

  • CVE-2010-3674MedNov 5, 2019
    risk 0.40cvss 6.1epss 0.01

    TYPO3 before 4.4.1 allows XSS in the frontend search box.

  • CVE-2005-2350MedNov 1, 2019
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.

  • CVE-2013-2012HigOct 31, 2019
    risk 0.40cvss 7.3epss 0.00

    autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.

  • CVE-2013-1951MedOct 31, 2019
    risk 0.40cvss 6.1epss 0.02

    A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.

  • CVE-2010-1673MedOct 30, 2019
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.

  • CVE-2019-16728MedSep 24, 2019
    risk 0.40cvss 6.1epss 0.02

    DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.

  • CVE-2019-16393MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.

  • CVE-2019-16392MedSep 17, 2019
    risk 0.40cvss 6.1epss 0.01

    SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.

  • CVE-2019-13274MedAug 27, 2019
    risk 0.40cvss 6.1epss 0.01

    In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.

  • CVE-2019-11041HigAug 9, 2019
    risk 0.40cvss 7.1epss 0.04

    When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This…

  • CVE-2019-12471MedJul 10, 2019
    risk 0.40cvss 6.1epss 0.01

    Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2019-10241MedApr 22, 2019
    risk 0.40cvss 6.1epss 0.10

    In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory…

  • CVE-2019-10904MedApr 6, 2019
    risk 0.40cvss 6.1epss 0.02

    Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.

  • CVE-2019-9741MedMar 13, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.

  • CVE-2016-10742MedFeb 17, 2019
    risk 0.40cvss 6.1epss 0.03

    Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.

  • CVE-2019-6799MedJan 26, 2019
    risk 0.40cvss 5.9epss 0.15

    An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the…

  • CVE-2018-19970MedDec 11, 2018
    risk 0.40cvss 6.1epss 0.02

    In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.

  • CVE-2018-6081MedNov 14, 2018
    risk 0.40cvss 6.1epss 0.01

    XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.

  • CVE-2018-6076MedNov 14, 2018
    risk 0.40cvss 6.1epss 0.01

    Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.

  • CVE-2018-6070MedNov 14, 2018
    risk 0.40cvss 6.1epss 0.01

    Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.

  • CVE-2018-16471MedNov 13, 2018
    risk 0.40cvss 6.1epss 0.02

    There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value…

  • CVE-2018-16845MedNov 7, 2018
    risk 0.40cvss 6.1epss 0.10

    nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.…

  • CVE-2018-18065MedOct 8, 2018
    risk 0.40cvss 6.5epss 0.17

    _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

  • CVE-2018-6046MedSep 25, 2018
    risk 0.40cvss 6.1epss 0.01

    Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.

  • CVE-2018-6039MedSep 25, 2018
    risk 0.40cvss 6.1epss 0.01

    Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.

  • CVE-2018-1000671MedSep 6, 2018
    risk 0.40cvss 6.1epss 0.04

    sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be…

  • CVE-2017-15429MedAug 28, 2018
    risk 0.40cvss 6.1epss 0.01

    Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

  • CVE-2017-15427MedAug 28, 2018
    risk 0.40cvss 6.1epss 0.01

    Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.

  • CVE-2018-14773MedAug 3, 2018
    risk 0.40cvss 6.5epss 0.58

    An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the…

  • CVE-2018-8032MedAug 2, 2018
    risk 0.40cvss 6.1epss 0.11

    Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

Page 110 of 210