Latest CVE Feed
-
4.0
MEDIUMCVE-2013-3448
Cisco WebEx Meetings Server does not check whether a user account is active, which allows remote authenticated users to bypass intended access restrictions by performing meeting operations after account deactivation, aka Bug ID CSCuh33315.... Read more
Affected Products : webex_meetings_server- Published: Aug. 02, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0168
The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of oth... Read more
Affected Products : enterprise_virtualization_manager- Published: Mar. 12, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-2685
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to cause a denial of service (memory consumption) via a large size in an image request.... Read more
- Published: Sep. 28, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0395
Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect integrity via unknown vectors related to Security.... Read more
Affected Products : peoplesoft_products- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-1907
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4 before 8.1.4.7 allows remote authenticated users to read cookies via unspecified vectors.... Read more
Affected Products : rational_license_key_server- Published: May. 08, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-2168
IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to obtain sensitive stack-trace information from CM server error messages via an invalid parameter.... Read more
Affected Products : rational_clearquest- Published: Aug. 17, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-3425
The Meeting Center component in Cisco WebEx 11 generates different error messages for invalid file-access attempts depending on whether a file exists, which allows remote authenticated users to enumerate files via a series of SPI calls, aka Bug ID CSCuc35... Read more
Affected Products : webex- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-6146
The Backend History Module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 does not properly restrict access, which allows remote authenticated editors to read the history of arbitrary records via a crafted URL.... Read more
Affected Products : typo3- Published: May. 20, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-4401
Moodle 2.2.x before 2.2.5 and 2.3.x before 2.3.2 allows remote authenticated users to bypass intended capability restrictions and perform certain topic changes by leveraging course-editing capabilities.... Read more
Affected Products : moodle- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0304
ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site requ... Read more
- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2008-4129
Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allows remote authenticated users to conduct directory traversal attacks and read arbitrary files via vectors related to the archive upload ... Read more
- Published: Sep. 18, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2013-0715
The WebCLI component in Wind River VxWorks 5.5 through 6.9 allows remote authenticated users to cause a denial of service (CLI session crash) via a crafted command string.... Read more
Affected Products : vxworks- Published: Mar. 20, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-3596
AdvancePro Advanceware allows remote authenticated users to obtain sensitive information about arbitrary customers' orders via a modified id parameter.... Read more
Affected Products : advanceware- Published: Sep. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0934
EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allows remote authenticated users to bypass intended access restrictions and modify global reports via unspecified vectors.... Read more
- Published: May. 07, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0212
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote ... Read more
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2020-24403
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorize... Read more
- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2014-4299
Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, C... Read more
Affected Products : database_server- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-3442
The web portal in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to obtain sensitive stack-trace information via unspecified vectors that trigger a stack exception, aka Bug ID CSCug34854.... Read more
Affected Products : unified_communications_manager- Published: Aug. 05, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-5966
The restricted telnet shell on the D-Link DSL2730U router allows remote authenticated users to bypass intended command restrictions via shell metacharacters that follow a whitelisted command.... Read more
Affected Products : dsl-2730u- Published: Dec. 13, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0330
Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to build arbitrary jobs via unknown attack vectors.... Read more
Affected Products : jenkins- Published: Mar. 19, 2013
- Modified: Apr. 11, 2025