Latest CVE Feed
-
4.0
MEDIUMCVE-2007-5232
Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when applet caching is enabled, allows remote attackers to violate the... Read more
- Published: Oct. 05, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-1948
The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses ... Read more
Affected Products : lotus_notes- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-2633
Absolute path traversal vulnerability in the copy action in index.php in Andrew Godwin ByteHoard 2.1 and earlier allows remote authenticated users to create or overwrite files in other users' directories by specifying the absolute path of the directory in... Read more
Affected Products : bytehoard- Published: May. 30, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-1147
The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remote attackers (possibly authenticated) to cause a denial of service (application crash) via a long skin, we... Read more
Affected Products : alien_arena_2006- Published: Mar. 10, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0424
BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7 allows remote authenticated guest users to read the server log and obtain sensitive configuration information.... Read more
Affected Products : weblogic_server- Published: Jan. 25, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-1119
fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.... Read more
- Published: Mar. 09, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0929
Directory traversal vulnerability in the IMAP server in ArGoSoft Mail Server Pro 1.8.8.1 allows remote authenticated users to create arbitrary folders via a .. (dot dot) in the RENAME command.... Read more
Affected Products : argosoft_mail_server- Published: Feb. 28, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-0445
index.php in Phpclanwebsite 1.23.1 allows remote authenticated users to obtain the installation path by specifying an invalid file name to the uploader page, as demonstrated by "\", which will display the full path of uploader.php. NOTE: this might be th... Read more
Affected Products : phpclanwebsite- Published: Jan. 26, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2007-3639
WordPress before 2.2.2 allows remote attackers to redirect visitors to other websites and potentially obtain sensitive information via (1) the _wp_http_referer parameter to wp-pass.php, related to the wp_get_referer function in wp-includes/functions.php; ... Read more
Affected Products : wordpress- Published: Jul. 10, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-1682
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.... Read more
- Published: May. 08, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-6610
Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which ... Read more
- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-6382
Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_I... Read more
Affected Products : linux_kernel- Published: Nov. 27, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-5413
HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to gain privileges and obtain sensitive information via unspecified vectors.... Read more
Affected Products : version_control_repository_manager- Published: Aug. 26, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2007-5239
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier does not properly enforce access restrictions for untrusted (1) applications and (2) ap... Read more
- Published: Oct. 06, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-3555
OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.... Read more
- Published: Jul. 23, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-2266
message/index.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 does not consider the moodle/site:readallmessages capability before accessing arbitrary conversations, which allows remote authenticated users to obt... Read more
Affected Products : moodle- Published: Jun. 01, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-6505
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to SERVER:MEMORY STORAGE ENGINE.... Read more
- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3621
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicur... Read more
- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-4761
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code.... Read more
Affected Products : websphere_portal- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2015-0439
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756.... Read more
- Published: Apr. 16, 2015
- Modified: Apr. 12, 2025