Latest CVE Feed
-
4.0
MEDIUMCVE-2015-8229
Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registered device.... Read more
- Published: Nov. 24, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-1991
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.... Read more
Affected Products : api_connect- Published: May. 22, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2015-6261
Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows remote authenticated users to bypass intended access restrictions and read configuration files by leveraging the Mobile and Remote Access (MRA) role and establishing a TFTP sessi... Read more
Affected Products : telepresence_video_communication_server_software- Published: Aug. 26, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-1962
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the logout button is pressed. The lack of proper session termination may allow attackers with local access to login into a closed browser session. IBM X-Force ID... Read more
Affected Products : security_identity_manager- Published: Feb. 04, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2007-6315
Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash) via a HTTP request to /eh/chat.ehintf/C. that does not contain a Connection ID, which results in a NULL pointer dereference.... Read more
- Published: Dec. 12, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-3555
OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.... Read more
- Published: Jul. 23, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-4761
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 before 8.0.0.1 CF14, and 8.5.0 through 8.5.0.0 CF02 allows remote authenticated users to discover credentials by reading HTML source code.... Read more
Affected Products : websphere_portal- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2019-16183
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.... Read more
Affected Products : limesurvey- Published: Sep. 09, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-3621
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicur... Read more
- Published: Oct. 02, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2005-3975
Interpretation conflict in file.inc in Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3 allows remote authenticated users to inject arbitrary web script or HTML via HTML in a file with a GIF or JPEG file extension, which causes the HTML to be executed b... Read more
Affected Products : drupal- Published: Dec. 03, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2014-3940
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a ra... Read more
- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2020-4846
IBM Security Key Lifecycle Manager 3.0.1 and 4.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-... Read more
Affected Products : security_key_lifecycle_manager- Published: Dec. 17, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2024-34670
Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.... Read more
Affected Products :- Published: Oct. 08, 2024
- Modified: Oct. 10, 2024
-
4.0
MEDIUMCVE-2024-36062
The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.andr... Read more
Affected Products :- Published: Nov. 07, 2024
- Modified: Feb. 10, 2025
-
4.0
MEDIUMCVE-2025-32996
In http-proxy-middleware before 2.0.8 and 3.x before 3.0.4, writeBody can be called twice because "else if" is not used.... Read more
Affected Products : http-proxy-middleware- Published: Apr. 15, 2025
- Modified: Apr. 15, 2025
-
4.0
MEDIUMCVE-2023-46181
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 269686.... Read more
Affected Products : sterling_secure_proxy- Published: Mar. 15, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2020-4906
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4 allows web pages to be stored locally which can be read by another user on the system.... Read more
- Published: Dec. 16, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2024-34677
Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.... Read more
- Published: Nov. 06, 2024
- Modified: Nov. 12, 2024
-
4.0
MEDIUMCVE-2015-0620
The XML parser in Cisco TelePresence Management Suite (TMS) 14.3(.2) and earlier does not properly handle external entities, which allows remote authenticated users to cause a denial of service via POST requests, aka Bug ID CSCus51494.... Read more
Affected Products : telepresence_management_suite- Published: Feb. 18, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2006-0127
Directory traversal vulnerability in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote authenticated users to rename the folders of other users via a .. (dot dot) in the RENAME command.... Read more
Affected Products : mailsite- Published: Jan. 09, 2006
- Modified: Apr. 03, 2025