Latest CVE Feed
-
4.0
MEDIUMCVE-2025-25765
MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.... Read more
Affected Products : mrcms- Published: Feb. 21, 2025
- Modified: Mar. 28, 2025
- Vuln Type: Misconfiguration
-
4.0
MEDIUMCVE-2008-1301
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 param... Read more
Affected Products : opencms- Published: Mar. 12, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2014-5214
nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing an XML external entity declaration in... Read more
- Published: Dec. 23, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2008-4041
The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource consumption and daemon crash) via a long IMAP APPEND command with certain repeated parameters.... Read more
Affected Products : softalk_mail_server- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2004-2520
POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.... Read more
Affected Products : gattaca_server_2003- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2008-4016
Unspecified vulnerability in the Collaborative Workspaces component in Oracle Collaboration Suite 10.1.2 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
Affected Products : collaboration_suite- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2004-2487
Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via (1) "..", (2) "\..\" (backslash dot dot), or (3) "/../" sequences in (a) RETR (get), (b) NLST (ls), (c) LIST (ls),... Read more
Affected Products : nexgen_ftp_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2004-2747
Directory traversal vulnerability in Pablo Software Solutions Quick 'n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which trigge... Read more
Affected Products : quick_n_easy_ftp_server- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2004-2659
Opera offers an Open button to verify that a user wishes to execute a downloaded file, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking Open via a request for a different mouse or keyboard action v... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2002-2175
phpSquidPass before 0.2 uses an incomplete regular expression to find a matching username in its database, which allows remote authenticated attackers to effectively delete other usernames via a short username that matches the end of the targeted username... Read more
Affected Products : phpsquidpass- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2013-5676
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.... Read more
- Published: Dec. 13, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-7330
Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related to post-build actions.... Read more
Affected Products : jenkins- Published: Oct. 17, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-6731
IBM Netezza Performance Portal 2.x before 2.0.0.3 allows remote authenticated users to change arbitrary passwords via an HTTP POST request.... Read more
Affected Products : netezza_performance_portal- Published: Feb. 26, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-9749
Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."... Read more
- Published: Nov. 06, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2013-4044
IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request.... Read more
Affected Products : spss_collaboration_and_deployment_services- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-4131
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE r... Read more
Affected Products : subversion- Published: Jul. 31, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-2506
app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.... Read more
Affected Products : spree- Published: Mar. 08, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-2761
The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via crafted FTP traffic, as demonstrated by the FileZilla FTP client.... Read more
Affected Products : modicon_m340- Published: Apr. 04, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2013-2979
Directory traversal vulnerability in IBM Optim Performance Manager 4.1.1 and IBM InfoSphere Optim Performance Manager 5.x before 5.2 allows remote authenticated users to read arbitrary files via a crafted URL.... Read more
- Published: Aug. 22, 2013
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-0308
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.... Read more
Affected Products : squid- Published: Feb. 03, 2010
- Modified: Apr. 11, 2025