Latest CVE Feed
-
4.0
MEDIUMCVE-2015-0251
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.... Read more
- Published: Apr. 08, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-1645
Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the publication template path.... Read more
Affected Products : open-xchange_server- Published: Sep. 05, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0168
The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of oth... Read more
Affected Products : enterprise_virtualization_manager- Published: Mar. 12, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-1619
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote a... Read more
Affected Products : gnutls- Published: Feb. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2014-4299
Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, C... Read more
Affected Products : database_server- Published: Oct. 15, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-0212
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote ... Read more
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-3839
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.... Read more
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0934
EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allows remote authenticated users to bypass intended access restrictions and modify global reports via unspecified vectors.... Read more
- Published: May. 07, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-2200
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspecified vectors.... Read more
Affected Products : wordpress- Published: Jul. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-2230
The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of service (daemon crash) via unspecified vectors involving "multiple events registration."... Read more
Affected Products : libvirt- Published: Sep. 30, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-3553
chan_skinny.c in the Skinny (aka SCCP) channel driver in Asterisk Open Source 10.x before 10.5.1 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by sending a Station Key Pad Button message and clo... Read more
- Published: Jun. 19, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-2214
status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegrou... Read more
Affected Products : nagios- Published: Feb. 10, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2024-21100
Vulnerability in the Oracle Commerce Platform product of Oracle Commerce (component: Platform). Supported versions that are affected are 11.3.0, 11.3.1 and 11.3.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access vi... Read more
Affected Products : commerce_platform- Published: Apr. 16, 2024
- Modified: Dec. 06, 2024
-
4.0
MEDIUMCVE-2013-2242
mod/chat/gui_sockets/index.php in Moodle through 2.1.10, 2.2.x before 2.2.11, 2.3.x before 2.3.8, 2.4.x before 2.4.5, and 2.5.x before 2.5.1 does not consider the mod/chat:chat capability before authorizing daemon-mode chat, which allows remote authentica... Read more
Affected Products : moodle- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-1585
OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.... Read more
Affected Products : nova- Published: Aug. 17, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-3834
Unspecified vulnerability in MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (server crash) via vectors related to "materializing a derived table that required a temporary tab... Read more
- Published: Jan. 14, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-0932
EMC RSA Archer 5.x before GRC 5.3SP1, and Archer Smart Suite Framework 4.x, allows remote authenticated users to bypass intended access restrictions and upload arbitrary files via unspecified vectors.... Read more
- Published: May. 07, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2012-6146
The Backend History Module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 does not properly restrict access, which allows remote authenticated editors to read the history of arbitrary records via a crafted URL.... Read more
Affected Products : typo3- Published: May. 20, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-0304
ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site requ... Read more
- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2020-24403
Magento version 2.4.0 and 2.3.5p1 (and earlier) are affected by an incorrect user permissions vulnerability within the Inventory component. This vulnerability could be abused by authenticated users with Inventory and Source permissions to make unauthorize... Read more
- Published: Nov. 09, 2020
- Modified: Nov. 21, 2024