Latest CVE Feed
-
4.0
MEDIUMCVE-2013-4485
389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request.... Read more
- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-0746
The disaster recovery system (DRS) in Cisco Unified Contact Center Express (Unified CCX) allows remote authenticated users to obtain sensitive information by reading extraneous fields in an HTML document, aka Bug ID CSCum95536.... Read more
Affected Products : unified_contact_center_express_editor_software- Published: Feb. 27, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-3959
The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated user... Read more
- Published: Jun. 14, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-2200
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.... Read more
Affected Products : wordpress- Published: Jul. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-0124
The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows... Read more
Affected Products : moodle- Published: Mar. 24, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-0820
Directory traversal vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to read arbitrary files via unspecified vectors.... Read more
Affected Products : garoon- Published: Feb. 27, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-0830
Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pathnam... Read more
Affected Products : financial_transaction_manager- Published: Feb. 01, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-2230
The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via unspecified vectors involving "multiple events registration."... Read more
Affected Products : libvirt- Published: Sep. 30, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-2242
mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authentica... Read more
Affected Products : moodle- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-4198
mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.... Read more
Affected Products : plone- Published: Mar. 11, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-2214
status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegrou... Read more
Affected Products : nagios- Published: Feb. 10, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-5096
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, a... Read more
- Published: Aug. 16, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-0140
Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.... Read more
- Published: Oct. 06, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-0863
The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in memory, which allows remote authenticated users to obtain sensitive cleartext information via an unspecified ... Read more
Affected Products : cognos_tm1- Published: Sep. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-0857
The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.... Read more
Affected Products : websphere_application_server- Published: May. 01, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-0215
The blind-marking implementation in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 allows remote authenticated users to de-anonymize student identities by (1) using a screen reader or (2) reading the HTML source.... Read more
Affected Products : moodle- Published: May. 27, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2012-3180
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.65 and earlier, and 5.5.27 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.... Read more
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-0220
Cloudera Manager before 4.8.3 and 5.x before 5.0.1 allows remote authenticated users to obtain sensitive configuration information via the API.... Read more
Affected Products : cloudera_manager- Published: Jun. 10, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2010-0308
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.... Read more
Affected Products : squid- Published: Feb. 03, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-3834
Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vectors related to "materializing a derived table that required a temporary tab... Read more
- Published: Jan. 14, 2011
- Modified: Apr. 11, 2025