Latest CVE Feed
-
4.0
MEDIUMCVE-2012-3150
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.64 and earlier, and 5.5.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.... Read more
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-5481
Moodle 2.3.x before 2.3.3 allows remote authenticated users to bypass the moodle/role:manage capability requirement and read all capability data by visiting the Check Permissions page.... Read more
Affected Products : moodle- Published: Nov. 21, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-2354
Moodle 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/site:readallmessages capability requirement and read arbitrary messages by using the "Recent conversations" feature with a modified parameter in a URL.... Read more
Affected Products : moodle- Published: Jul. 21, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-3117
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, and 6.2 allows remote authenticated users to affect confidentiality via unknown vectors related to HTTP.... Read more
Affected Products : supply_chain_products_suite- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-2373
The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial of service (panic) via a crafted application that trigge... Read more
Affected Products : linux_kernel- Published: Aug. 09, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-5472
lib/formslib.php in Moodle 2.2.x before 2.2.6 and 2.3.x before 2.3.3 allows remote authenticated users to bypass intended access restrictions via a modified value of a frozen form field.... Read more
Affected Products : moodle- Published: Nov. 21, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-4362
hydra.exe in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance has a hardcoded password of L0CAlu53R for the global$agent account, which allows remote attackers to obtain access to a management service via a login: request to TCP port 13838.... Read more
- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2024-22338
IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to hazardous input validation. IBM X-Force ID: 279978.... Read more
Affected Products : security_verify_access_oidc_provider- Published: May. 31, 2024
- Modified: Aug. 14, 2025
-
4.0
MEDIUMCVE-2012-4847
IBM Cognos Business Intelligence (BI) 8.4 and 8.4.1 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted request containing a zero-valued byte.... Read more
Affected Products : cognos_business_intelligence- Published: Nov. 14, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-0101
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0087 and CVE-2012-0102.... Read more
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-5336
lib/base.php in ownCloud before 4.0.8 does not properly validate the user_id session variable, which allows remote authenticated users to read arbitrary files via vectors related to WebDAV.... Read more
- Published: Jun. 04, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-4198
The User.get method in Bugzilla/WebService/User.pm in Bugzilla 3.7.x and 4.0.x before 4.0.9, 4.1.x and 4.2.x before 4.2.4, and 4.3.x and 4.4.x before 4.4rc1 has a different outcome for a groups request depending on whether a group exists, which allows rem... Read more
Affected Products : bugzilla- Published: Nov. 16, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-4421
The create_post function in wp-includes/class-wp-atom-server.php in WordPress before 3.4.2 does not perform a capability check, which allows remote authenticated users to bypass intended access restrictions and publish new posts by leveraging the Contribu... Read more
Affected Products : wordpress- Published: Sep. 14, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-0290
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning att... Read more
Affected Products : bind- Published: Jan. 22, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2019-2730
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior and 5.7.18 and prior. Easily exploitable vulnerability allows high privileged attacker with... Read more
- Published: Jul. 23, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2012-5335
Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the URI of an HTTP request.... Read more
Affected Products : tiny_server- Published: Oct. 08, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-3553
chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by sending a Station Key Pad Button message and clo... Read more
- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-2315
admin/Auth in OpenKM 5.1.7 and other versions before 5.1.8-2 does not properly enforce privileges for changing user roles, which allows remote authenticated users to assign administrator privileges to arbitrary users via the userEdit action.... Read more
Affected Products : openkm- Published: Sep. 09, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-2498
Cisco AnyConnect Secure Mobility Client 3.0 through 3.0.08066 does not ensure that authentication makes use of a legitimate certificate, which allows user-assisted man-in-the-middle attackers to spoof servers via a crafted certificate, aka Bug ID CSCtz291... Read more
Affected Products : anyconnect_secure_mobility_client- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-4413
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles, which allows remote authenticated users to retain the privileges of the revoked roles.... Read more
Affected Products : keystone- Published: Sep. 18, 2012
- Modified: Apr. 11, 2025