Latest CVE Feed
-
4.0
MEDIUMCVE-2014-1476
The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.... Read more
Affected Products : drupal- Published: Jan. 24, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2020-28923
An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior to 2.8.0 that used the Play Java API to serialize classe... Read more
Affected Products : play_framework- Published: Dec. 03, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2008-0658
slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.... Read more
Affected Products : openldap- Published: Feb. 13, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-2366
upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.... Read more
- Published: Jul. 19, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-2588
Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter.... Read more
Affected Products : asset_manager- Published: Mar. 24, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-2494
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to ENARC.... Read more
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3294
Cisco WebEx Meeting Server does not properly restrict the content of URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID C... Read more
Affected Products : webex_meetings_server- Published: Jun. 10, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3323
Directory traversal vulnerability in Cisco Unified Contact Center Enterprise allows remote authenticated users to read arbitrary web-root files via a crafted URL, aka Bug ID CSCun25262.... Read more
- Published: Jul. 18, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-1643
The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allows remote authenticated users to read the stored outbound e-mail messages of arbitrary users via a modified URL.... Read more
Affected Products : encryption_management_server- Published: Feb. 07, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-2404
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10.1.4.3, 11.1.1.3.0, 11.1.1.5.0, 11.1.1.7.0, 11.1.2.0.0, 11.1.2.1.0, and 11.1.2.2.0 allows remote authenticated users to affect confidentiality via unknown vecto... Read more
Affected Products : fusion_middleware- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2016-9844
Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.... Read more
Affected Products : unzip- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2014-2151
The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information via a crafted JavaScript file, aka Bug ID CSCui04520.... Read more
Affected Products : adaptive_security_appliance_software- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3132
SAP Background Processing does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1.... Read more
Affected Products : background_processing- Published: Apr. 30, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3667
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.... Read more
- Published: Oct. 16, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-6064
The Accounts tab in the administrative user interface in McAfee Web Gateway (MWG) before 7.3.2.9 and 7.4.x before 7.4.2 allows remote authenticated users to obtain the hashed user passwords via unspecified vectors.... Read more
Affected Products : web_gateway- Published: Sep. 02, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-6404
Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/se... Read more
Affected Products : quassel_irc- Published: Dec. 09, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-2522
curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate wh... Read more
- Published: Apr. 18, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-3225
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.... Read more
Affected Products : cobbler- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2008-1301
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 param... Read more
Affected Products : opencms- Published: Mar. 12, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2007-4319
The management interface in ZyNOS firmware 3.62(WK.6) on the Zyxel Zywall 2 device allows remote authenticated administrators to cause a denial of service (infinite reboot loop) via invalid configuration data. NOTE: this issue might not cross privilege b... Read more
- Published: Aug. 13, 2007
- Modified: Apr. 09, 2025