Latest CVE Feed
-
4.0
MEDIUMCVE-2009-5012
ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.... Read more
Affected Products : pyftpdlib- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-5006
The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to caus... Read more
- Published: Oct. 18, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2006-5540
backend/parser/analyze.c in PostgreSQL 8.1.x before 8.1.5 allows remote authenticated users to cause a denial of service (daemon crash) via certain aggregate functions in an UPDATE statement, which are not properly handled during a "MIN/MAX index optimiza... Read more
Affected Products : postgresql- Published: Oct. 26, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-4019
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the G... Read more
- Published: Nov. 30, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-2077
Drupal 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to bypass access restrictions and (1) read unpublished content from anonymous users when a view is already configured to display the content, and (2) read private content in... Read more
- Published: Jun. 16, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-2125
delete_bug.php in Elvin before 1.2.1 does not require administrative privileges, which allows remote authenticated users to bypass intended access restrictions and delete arbitrary bugs.... Read more
Affected Products : elvinbts- Published: Jun. 19, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-3404
Unspecified vulnerability in the PeopleSoft PeopleTools & Enterprise Portal component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.23 allows remote authenticated users to affect integrity via unknown vectors.... Read more
- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2010-0422
gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, which allows physically proximate attackers to bypass screen locking and acc... Read more
Affected Products : screensaver- Published: Feb. 24, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-4467
misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail action with the valmem set to a pre-assigned user ID, which is visible from a memberlist action.... Read more
Affected Products : deluxebb- Published: Dec. 30, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-3545
DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command.... Read more
Affected Products : ftpxq_server- Published: Oct. 05, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2020-13308
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a project that had 2 factor authentication inheritance.... Read more
Affected Products : gitlab- Published: Sep. 15, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2009-4048
Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE command to one socket in conjunction with a DELE command to a second socket.... Read more
Affected Products : xm_easy_personal_ftp_server- Published: Nov. 23, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-2355
The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (application crash) by specifying (1) an empty string or (2) a non-numeric string when selecting a forum, related to the fmessagelist function.... Read more
Affected Products : nulllogic_groupware- Published: Jul. 07, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2009-2171
Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user's artefact.... Read more
Affected Products : mahara- Published: Jun. 23, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2010-0451
The installation process for NFS/ONCplus B.11.31_08 and earlier on HP HP-UX B.11.31 changes the NFS_SERVER setting in the nfsconf file, which might allow remote attackers to obtain filesystem access via NFS requests.... Read more
Affected Products : hp-ux- Published: Mar. 29, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-4658
Xerver 4.32 allows remote authenticated users to cause a denial of service (daemon crash) via a non-numeric web port assignment in the management interface. NOTE: this can be leveraged by non-authenticated attackers using CVE-2009-4657.... Read more
Affected Products : xerver- Published: Mar. 03, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2024-23765
An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port 7412 on the network. All the network services of the gateway become unresponsive after sending 85 requests to this port. The content an... Read more
Affected Products :- Published: Jun. 26, 2024
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-52924
In One Identity OneLogin before 2025.2.0, the SQL connection "application name" is set based on the value of an untrusted X-RequestId HTTP request header.... Read more
Affected Products :- Published: Jul. 19, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
4.0
MEDIUMCVE-2021-20478
IBM Cloud Pak System 2.3 could allow a local user in some situations to view the artifacts of another user in self service console. IBM X-Force ID: 197497.... Read more
Affected Products : cloud_pak_system- Published: Jul. 20, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2024-34599
Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.... Read more
- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024