Latest CVE Feed
-
4.0
MEDIUMCVE-2013-6303
Directory traversal vulnerability in IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0, and ACSWeb in AlgoWebApps 5.0.0, allows remote authenticated users t... Read more
Affected Products : algo_one- Published: Mar. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-6978
The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device information by reading "extraneous information" in HTML source code, aka Bug ID CSCu... Read more
Affected Products : unified_communications_manager- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-6214
Unspecified vulnerability in the Integration Service in HP Universal Configuration Management Database 9.05, 10.01, and 10.10 allows remote authenticated users to obtain sensitive information via unknown vectors, aka ZDI-CAN-2042.... Read more
Affected Products : universal_configuration_management_database- Published: Apr. 19, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-6404
Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/se... Read more
Affected Products : quassel_irc- Published: Dec. 09, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-6731
IBM Netezza Performance Portal 2.x before 2.0.0.3 allows remote authenticated users to change arbitrary passwords via an HTTP POST request.... Read more
Affected Products : netezza_performance_portal- Published: Feb. 26, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-7330
Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related to post-build actions.... Read more
Affected Products : jenkins- Published: Oct. 17, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-0015
cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.... Read more
- Published: Feb. 02, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-6241
The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, in certain user-id sharing scenarios, does not properly construct a SQL statement for next-year birthdays, which allows remote authenti... Read more
Affected Products : open-xchange_appsuite- Published: Dec. 27, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-0377
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality via vectors related to SYS tables.... Read more
Affected Products : database_server- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-5767
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.... Read more
Affected Products : mysql- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-6422
The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof... Read more
- Published: Dec. 23, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-6304
Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.... Read more
- Published: Mar. 06, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2011-4347
The kvm_vm_ioctl_assign_device function in virt/kvm/assigned-dev.c in the KVM subsystem in the Linux kernel before 3.1.10 does not verify permission to access PCI configuration space and BAR resources, which allows host OS users to assign PCI devices and ... Read more
Affected Products : linux_kernel- Published: Jun. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-5756
Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to cgi-bin/cgiServer.exx.... Read more
Affected Products : sip-t38g- Published: Aug. 03, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-1672
Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, which allows attackers to bypass intended access restriction... Read more
- Published: Jan. 26, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-3825
Unspecified vulnerability in the Oracle Agile Product Collaboration component in Oracle Supply Chain Products Suite 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Folders & Files Attachment.... Read more
Affected Products : supply_chain_products_suite- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-3766
Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.1, 8.2, and 8.3 allows remote authenticated users to affect integrity via unknown vectors related to Web Access.... Read more
Affected Products : primavera_products_suite- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2011-3346
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command. NOT... Read more
- Published: Apr. 01, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-3796
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.... Read more
Affected Products : mysql- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-3823
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- Published: Jul. 17, 2013
- Modified: Apr. 11, 2025