Latest CVE Feed
-
4.0
MEDIUMCVE-2021-2326
Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to... Read more
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2017-20191
A vulnerability was found in Zimbra zm-admin-ajax up to 8.8.1. It has been classified as problematic. This affects the function XFormItem.prototype.setError of the file WebRoot/js/ajax/dwt/xforms/XFormItem.js of the component Form Textbox Field Error Hand... Read more
Affected Products :- Published: Mar. 31, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2006-2900
Internet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the... Read more
- Published: Jun. 07, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2020-10457
Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) and imgUrl (for th... Read more
Affected Products : phpkb- Published: Mar. 12, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2008-7182
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND comm... Read more
Affected Products : surgemail- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-7289
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by makin... Read more
Affected Products : tivoli_directory_server- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2006-4938
help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might allow remote authenticated users to obtain the path in an error message.... Read more
Affected Products : moodle- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2020-11686
In JetBrains TeamCity before 2019.1.4, a project administrator was able to retrieve some TeamCity server settings.... Read more
Affected Products : teamcity- Published: Apr. 22, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2008-7264
The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed data-transfer attempt.... Read more
Affected Products : pyftpdlib- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2008-7290
Memory leak in the ldap_explode_rdn API function in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allows remote authenticated users to cause a denial of service (memory consumption) by making many function calls.... Read more
Affected Products : tivoli_directory_server- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2020-13342
An issue has been discovered in GitLab affecting versions prior to 13.2.10, 13.3.7 and 13.4.2: Lack of Rate Limiting at Re-Sending Confirmation Email... Read more
Affected Products : gitlab- Published: Oct. 07, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2008-7287
Multiple memory leaks in the (1) ldap_init and (2) ldap_url_search_direct API functions in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 allow remote authenticated users to cause a denial of service (memory consumption) by making ma... Read more
Affected Products : tivoli_directory_server- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2006-2185
PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the groupOperationsMethod function fails, which allows context-dependent attackers to gain privileges.... Read more
Affected Products : netware- Published: May. 22, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2008-5742
Multiple open redirect vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the redirect parameter in a logoff action to modules/auth/index.php or (2) the url ... Read more
Affected Products : netcat- Published: Dec. 26, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2008-5846
Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."... Read more
Affected Products : movable_type- Published: Jan. 05, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-2717
Unspecified vulnerability in Secure Elements Class 5 AVR client and server (aka C5 EVM) before 2.8.1 allows authenticated attackers to overwrite arbitrary files (1) on a server during an update or (2) on a client via modified pathnames, possibly due to a ... Read more
Affected Products : c5_enterprise_vulnerability_management- Published: May. 31, 2006
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2006-5119
Multiple cross-site scripting (XSS) vulnerabilities in Zen Cart 1.3.5 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_name or (2) admin_pass parameter in (a) admin/login.php, or the (3) admin_email parameter in (b) admin/pa... Read more
- Published: Oct. 03, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-1004
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality and integrity via unknown vectors.... Read more
Affected Products : bea_product_suite- Published: Apr. 15, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-0897
IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the "schema DB2 instance id" and the bcgarchive (aka the archiver script).... Read more
Affected Products : websphere_partner_gateway- Published: May. 21, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2015-0409
Unspecified vulnerability in Oracle MySQL Server 5.6.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.... Read more
- Published: Jan. 21, 2015
- Modified: Apr. 12, 2025