Latest CVE Feed
-
4.3
MEDIUMCVE-2015-5335
Cross-site request forgery (CSRF) vulnerability in admin/registration/register.php in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote attackers to hijack the authentication of administrators for request... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-7789
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to cause a denial of service via unspecified vectors.... Read more
- Published: Dec. 30, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5204
CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.... Read more
Affected Products : cordova_file_transfer- Published: Dec. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5537
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerabil... Read more
- Published: Aug. 03, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2018-17204
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 ... Read more
- Published: Sep. 19, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-5309
Integer overflow in the terminal emulator in PuTTY before 0.66 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via an ECH (erase characters) escape sequence with a large parameter value, which tr... Read more
- Published: Dec. 07, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5342
The choice module in Moodle through 2.6.11, 2.7.x before 2.7.11, 2.8.x before 2.8.9, and 2.9.x before 2.9.3 allows remote authenticated users to bypass intended access restrictions by visiting a URL to add or delete responses in the closed state.... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5235
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.... Read more
- Published: Oct. 09, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5272
The Forum module in Moodle 2.7.x before 2.7.10 allows remote authenticated users to post to arbitrary groups by leveraging the teacher role, as demonstrated by a post directed to "all participants."... Read more
Affected Products : moodle- Published: Feb. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8309
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."... Read more
Affected Products : cherrymusic- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1000395
Jenkins 2.73.1 and earlier, 2.83 and earlier provides information about Jenkins user accounts which is generally available to anyone with Overall/Read permissions via the /user/(username)/api remote API. This included e.g. Jenkins users' email addresses i... Read more
Affected Products : jenkins- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2015-8336
Huawei FusionCompute with software before V100R005C10SPC700 allows remote authenticated users to obtain sensitive "role and permission" information via unspecified vectors.... Read more
- Published: Apr. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8509
Template.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.16, 4.3.x and 4.4.x before 4.4.11, and 4.5.x and 5.0.x before 5.0.2 does not properly construct CSV files, which allows remote attackers to obtain sensitive information by leveraging a web browser that ... Read more
Affected Products : bugzilla- Published: Jan. 03, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2019-13705
Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension.... Read more
- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0320
IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legitimately triggered processes.... Read more
Affected Products : urbancode_deploy- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-0308
IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images.... Read more
Affected Products : connections- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2019-13715
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.... Read more
- Published: Nov. 25, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-0343
IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authenticated users to obtain sensitive information by reading an error message. IBM X-Force ID: 111784.... Read more
Affected Products : tririga_application_platform- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-9710
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.... Read more
- Published: Aug. 19, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-42505
An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0.... Read more
Affected Products : superset- Published: Nov. 28, 2023
- Modified: Feb. 13, 2025