Latest CVE Feed
-
4.0
MEDIUMCVE-2021-36057
XMP Toolkit SDK version 2020.1 (and earlier) is affected by a write-what-where condition vulnerability caused during the application's memory allocation process. This may cause the memory management functions to become mismatched resulting in local applic... Read more
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2004-2769
Cerberus FTP Server before 4.0.3.0 allows remote authenticated users to list hidden files, even when the "Display hidden files" option is enabled, via the (1) MLSD or (2) MLST commands.... Read more
Affected Products : ftp_server- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2006-6915
ftpd in IBM AIX 5.2.0 and 5.3.0 allows remote authenticated users to cause a denial of service (port exhaustion) via unspecified vectors. NOTE: some details were obtained from third party sources.... Read more
Affected Products : aix- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2007-2583
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer d... Read more
- Published: May. 10, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2012-3391
mod/forum/rsslib.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not properly implement the requirement for posting before reading a Q&A forum, which allows remote authenticated users to bypass intended access restrictions by leveraging the s... Read more
Affected Products : moodle- Published: Jul. 23, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-3839
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-5335
Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the URI of an HTTP request.... Read more
Affected Products : tiny_server- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2011-4927
Unspecified vulnerability in the bazaar repository adapter in Redmine 1.0.x before 1.0.5 allows remote authenticated users to obtain sensitive information via unknown vectors.... Read more
Affected Products : redmine- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-3553
chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by sending a Station Key Pad Button message and clo... Read more
- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-4198
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows rem... Read more
Affected Products : bugzilla- Published: Nov. 16, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-4837
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.... Read more
Affected Products : cognos_business_intelligence- Published: Mar. 05, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-2927
The TM Software Tempo plugin before 6.4.3.1, 6.5.x before 6.5.0.2, and 7.x before 7.0.3 for Atlassian JIRA does not properly restrict the capabilities of third-party XML parsers, which allows remote authenticated users to cause a denial of service (resour... Read more
- Published: May. 22, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-3398
Algorithmic complexity vulnerability in Moodle 1.9.x before 1.9.19, 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to cause a denial of service (CPU consumption) by using the advanced-search feature on a ... Read more
Affected Products : moodle- Published: Jul. 23, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-5481
Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.... Read more
Affected Products : moodle- Published: Nov. 21, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-3096
Cisco Unity Connection (UC) 7.1, 8.0, and 8.5 allows remote authenticated users to cause a denial of service (resource consumption and administration outage) via extended use of the product, aka Bug ID CSCtd79132.... Read more
Affected Products : unity_connection- Published: Sep. 16, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-2948
chan_skinny.c in the Skinny (aka SCCP) channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1 allows remote authenticated users to cause a denial of service (NULL pointer ... Read more
- Published: Jun. 02, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-2373
The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial of service (panic) via a crafted application that trigge... Read more
Affected Products : linux_kernel- Published: Aug. 09, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2024-22338
IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: 279978.... Read more
Affected Products : security_verify_access_oidc_provider- Published: May. 31, 2024
- Modified: Aug. 14, 2025
-
4.0
MEDIUMCVE-2012-5158
Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.... Read more
- Published: Mar. 14, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-5336
lib/base.php in ownCloud before 4.0.8 does not properly validate the user_id session variable, which allows remote authenticated users to read arbitrary files via vectors related to WebDAV.... Read more
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025