Vendor CVEs
Debian
All CVEs
10,468 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-15676 | Med | 0.40 | 6.1 | 0.02 | Oct 1, 2020 | Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and… | ||
| CVE-2020-25626 | Med | 0.40 | 6.1 | 0.01 | Sep 30, 2020 | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject… | ||
| CVE-2019-14904 | Hig | 0.40 | 7.3 | 0.00 | Aug 26, 2020 | A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw… | ||
| CVE-2020-6535 | Med | 0.40 | 6.1 | 0.01 | Jul 22, 2020 | Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. | ||
| CVE-2020-6470 | Med | 0.40 | 6.1 | 0.01 | May 21, 2020 | Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents. | ||
| CVE-2020-12137 | Med | 0.40 | 6.1 | 0.02 | Apr 24, 2020 | GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform… | ||
| CVE-2020-8647 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2020 | There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c. | ||
| CVE-2020-7106 | Med | 0.40 | 6.1 | 0.02 | Jan 16, 2020 | Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is… | ||
| CVE-2019-17022 | Med | 0.40 | 6.1 | 0.02 | Jan 8, 2020 | When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage;… | ||
| CVE-2019-17016 | Med | 0.40 | 6.1 | 0.02 | Jan 8, 2020 | When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and… | ||
| CVE-2014-4913 | Med | 0.40 | 6.1 | 0.01 | Dec 15, 2019 | ZF2014-03 has a potential cross site scripting vector in multiple view helpers | ||
| CVE-2013-4158 | Med | 0.40 | 6.1 | 0.01 | Dec 11, 2019 | smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) | ||
| CVE-2019-19709 | Med | 0.40 | 6.1 | 0.02 | Dec 11, 2019 | MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page. | ||
| CVE-2012-1115 | Med | 0.40 | 6.1 | 0.02 | Dec 5, 2019 | A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php. | ||
| CVE-2012-1114 | Med | 0.40 | 6.1 | 0.02 | Dec 5, 2019 | A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php. | ||
| CVE-2012-0812 | Med | 0.40 | 6.1 | 0.01 | Nov 22, 2019 | PostfixAdmin 2.3.4 has multiple XSS vulnerabilities | ||
| CVE-2011-0544 | Med | 0.40 | 6.1 | 0.01 | Nov 14, 2019 | phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag. | ||
| CVE-2009-5046 | Med | 0.40 | 6.1 | 0.02 | Nov 6, 2019 | JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22. | ||
| CVE-2009-5049 | Med | 0.40 | 6.1 | 0.02 | Nov 6, 2019 | WebApp JSP Snoop page XSS in jetty though 6.1.21. | ||
| CVE-2010-2471 | Med | 0.40 | 6.1 | 0.01 | Nov 6, 2019 | Drupal versions 5.x and 6.x has open redirection | ||
| CVE-2010-3674 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2019 | TYPO3 before 4.4.1 allows XSS in the frontend search box. | ||
| CVE-2005-2350 | Med | 0.40 | 6.1 | 0.01 | Nov 1, 2019 | Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface. | ||
| CVE-2013-2012 | Hig | 0.40 | 7.3 | 0.00 | Oct 31, 2019 | autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory. | ||
| CVE-2013-1951 | Med | 0.40 | 6.1 | 0.02 | Oct 31, 2019 | A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names. | ||
| CVE-2010-1673 | Med | 0.40 | 6.1 | 0.01 | Oct 30, 2019 | A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment. | ||
| CVE-2019-16728 | Med | 0.40 | 6.1 | 0.02 | Sep 24, 2019 | DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari. | ||
| CVE-2019-16393 | Med | 0.40 | 6.1 | 0.01 | Sep 17, 2019 | SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character. | ||
| CVE-2019-16392 | Med | 0.40 | 6.1 | 0.01 | Sep 17, 2019 | SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages. | ||
| CVE-2019-13274 | Med | 0.40 | 6.1 | 0.01 | Aug 27, 2019 | In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter. | ||
| CVE-2019-11041 | Hig | 0.40 | 7.1 | 0.04 | Aug 9, 2019 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This… | ||
| CVE-2019-12471 | Med | 0.40 | 6.1 | 0.01 | Jul 10, 2019 | Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6. | ||
| CVE-2019-10241 | Med | 0.40 | 6.1 | 0.10 | Apr 22, 2019 | In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory… | ||
| CVE-2019-10904 | Med | 0.40 | 6.1 | 0.02 | Apr 6, 2019 | Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors. | ||
| CVE-2019-9741 | Med | 0.40 | 6.1 | 0.02 | Mar 13, 2019 | An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command. | ||
| CVE-2016-10742 | Med | 0.40 | 6.1 | 0.03 | Feb 17, 2019 | Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter. | ||
| CVE-2019-6799 | Med | 0.40 | 5.9 | 0.15 | Jan 26, 2019 | An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the… | ||
| CVE-2018-19970 | Med | 0.40 | 6.1 | 0.02 | Dec 11, 2018 | In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name. | ||
| CVE-2018-6081 | Med | 0.40 | 6.1 | 0.01 | Nov 14, 2018 | XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page. | ||
| CVE-2018-6076 | Med | 0.40 | 6.1 | 0.01 | Nov 14, 2018 | Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page. | ||
| CVE-2018-6070 | Med | 0.40 | 6.1 | 0.01 | Nov 14, 2018 | Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. | ||
| CVE-2018-16471 | Med | 0.40 | 6.1 | 0.02 | Nov 13, 2018 | There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value… | ||
| CVE-2018-16845 | Med | 0.40 | 6.1 | 0.10 | Nov 7, 2018 | nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.… | ||
| CVE-2018-18065 | Med | 0.40 | 6.5 | 0.17 | Oct 8, 2018 | _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | ||
| CVE-2018-6046 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2018 | Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension. | ||
| CVE-2018-6039 | Med | 0.40 | 6.1 | 0.01 | Sep 25, 2018 | Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension. | ||
| CVE-2018-1000671 | Med | 0.40 | 6.1 | 0.04 | Sep 6, 2018 | sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be… | ||
| CVE-2017-15429 | Med | 0.40 | 6.1 | 0.01 | Aug 28, 2018 | Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. | ||
| CVE-2017-15427 | Med | 0.40 | 6.1 | 0.01 | Aug 28, 2018 | Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar. | ||
| CVE-2018-14773 | Med | 0.40 | 6.5 | 0.58 | Aug 3, 2018 | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the… | ||
| CVE-2018-8032 | Med | 0.40 | 6.1 | 0.11 | Aug 2, 2018 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. |
- risk 0.40cvss 6.1epss 0.02
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and…
- risk 0.40cvss 6.1epss 0.01
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject…
- risk 0.40cvss 7.3epss 0.00
A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the remote machine. An attacker could take advantage of this flaw…
- risk 0.40cvss 6.1epss 0.01
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.
- risk 0.40cvss 6.1epss 0.01
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject arbitrary scripts or HTML (UXSS) via crafted clipboard contents.
- risk 0.40cvss 6.1epss 0.02
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform…
- risk 0.40cvss 6.1epss 0.00
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
- risk 0.40cvss 6.1epss 0.02
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is…
- risk 0.40cvss 6.1epss 0.02
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage;…
- risk 0.40cvss 6.1epss 0.02
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and…
- risk 0.40cvss 6.1epss 0.01
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
- risk 0.40cvss 6.1epss 0.01
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
- risk 0.40cvss 6.1epss 0.02
MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1 in the action API when editing that page.
- risk 0.40cvss 6.1epss 0.02
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
- risk 0.40cvss 6.1epss 0.02
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
- risk 0.40cvss 6.1epss 0.01
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities
- risk 0.40cvss 6.1epss 0.01
phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.
- risk 0.40cvss 6.1epss 0.02
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
- risk 0.40cvss 6.1epss 0.02
WebApp JSP Snoop page XSS in jetty though 6.1.21.
- risk 0.40cvss 6.1epss 0.01
Drupal versions 5.x and 6.x has open redirection
- risk 0.40cvss 6.1epss 0.01
TYPO3 before 4.4.1 allows XSS in the frontend search box.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.
- risk 0.40cvss 7.3epss 0.00
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.
- risk 0.40cvss 6.1epss 0.02
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.
- risk 0.40cvss 6.1epss 0.02
DOMPurify before 2.0.1 allows XSS because of innerHTML mutation XSS (mXSS) for an SVG element or a MATH element, as demonstrated by Chrome and Safari.
- risk 0.40cvss 6.1epss 0.01
SPIP before 3.1.11 and 3.2 before 3.2.5 mishandles redirect URLs in ecrire/inc/headers.php with a %0D, %0A, or %20 character.
- risk 0.40cvss 6.1epss 0.01
SPIP before 3.1.11 and 3.2 before 3.2.5 allows prive/formulaires/login.php XSS via error messages.
- risk 0.40cvss 6.1epss 0.01
In Xymon through 4.3.28, an XSS vulnerability exists in the csvinfo CGI script due to insufficient filtering of the db parameter.
- risk 0.40cvss 7.1epss 0.04
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This…
- risk 0.40cvss 6.1epss 0.01
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
- risk 0.40cvss 6.1epss 0.10
In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory…
- risk 0.40cvss 6.1epss 0.02
Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.
- risk 0.40cvss 6.1epss 0.02
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
- risk 0.40cvss 6.1epss 0.03
Zabbix before 2.2.21rc1, 3.x before 3.0.13rc1, 3.1.x and 3.2.x before 3.2.10rc1, and 3.3.x and 3.4.x before 3.4.4rc1 allows open redirect via the request parameter.
- risk 0.40cvss 5.9epss 0.15
An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is related to the…
- risk 0.40cvss 6.1epss 0.02
In phpMyAdmin before 4.8.4, an XSS vulnerability was found in the navigation tree, where an attacker can deliver a payload to a user through a crafted database/table name.
- risk 0.40cvss 6.1epss 0.01
XSS vulnerabilities in Interstitials in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension or open Developer Console to inject arbitrary scripts or HTML via a crafted HTML page.
- risk 0.40cvss 6.1epss 0.01
Insufficient encoding of URL fragment identifiers in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to perform a DOM based XSS attack via a crafted HTML page.
- risk 0.40cvss 6.1epss 0.01
Lack of CSP enforcement on WebUI pages in Bink in Google Chrome prior to 65.0.3325.146 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension.
- risk 0.40cvss 6.1epss 0.02
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value…
- risk 0.40cvss 6.1epss 0.10
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file.…
- risk 0.40cvss 6.5epss 0.17
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
- risk 0.40cvss 6.1epss 0.01
Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.
- risk 0.40cvss 6.1epss 0.01
Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.
- risk 0.40cvss 6.1epss 0.04
sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be…
- risk 0.40cvss 6.1epss 0.01
Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
- risk 0.40cvss 6.1epss 0.01
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
- risk 0.40cvss 6.5epss 0.58
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the…
- risk 0.40cvss 6.1epss 0.11
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Page 110 of 210