Latest CVE Feed
-
4.0
MEDIUMCVE-2010-3980
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 does not limit the number of CUIDs that may be requested, which allows remote authenticated users to cause a denial of service via a large numCuids value in a GenerateCuids SOAPAction to the dswsbobje/ser... Read more
Affected Products : businessobjects- Published: Oct. 18, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-6371
Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621.... Read more
- Published: Nov. 19, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-0438
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via unknown vectors related to Panel Processor.... Read more
Affected Products : peoplesoft_products- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2011-4593
Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 does not properly handle user/action_redir group messages, which allows remote authenticated users to discover e-mail addresses by visiting the messaging interface.... Read more
Affected Products : moodle- Published: Jul. 20, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2010-3519
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.49.28 and 8.50.12 allows remote authenticated users to affect integrity via unknown vectors.... Read more
Affected Products : peoplesoft_and_jdedwards_product_suite- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2015-6300
Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694.... Read more
- Published: Sep. 20, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-1991
IBM API Connect 5.0.0.0, and 5.0.8.6 could could return sensitive information that could provide critical information as to the underlying software stack in CMC UI headers. IBM X-Force ID: 154284.... Read more
Affected Products : api_connect- Published: May. 22, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2018-20932
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2012-4585
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to read arbitrary files via a crafted URL.... Read more
- Published: Aug. 22, 2012
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2007-0283
Unspecified vulnerability in Oracle Application Server 9.0.4.3 and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to Oracle Containers for J2EE, aka OC4J02.... Read more
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2015-5712
Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x before 7.0.1 and Spotfire Analytics Platform before 7.0.2 for AWS Marketplace allow remote authenticated u... Read more
- Published: Oct. 28, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2018-10521
In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file movement vulnerability that can cause DoS, exploitable by an admin user, because config.php can be moved into an incorrect directory.... Read more
Affected Products : cms_made_simple- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
4.0
MEDIUMCVE-2025-29839
Out-of-bounds read in Windows File Server allows an unauthorized attacker to disclose information locally.... Read more
Affected Products : windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_server_2022 windows_11_22h2 +9 more products- Published: May. 13, 2025
- Modified: May. 19, 2025
- Vuln Type: Information Disclosure
-
4.0
MEDIUMCVE-2021-47096
In the Linux kernel, the following vulnerability has been resolved: ALSA: rawmidi - fix the uninitalized user_pversion The user_pversion was uninitialized for the user space file structure in the open function, because the file private structure use kma... Read more
Affected Products : linux_kernel- Published: Mar. 04, 2024
- Modified: Apr. 08, 2025
-
4.0
MEDIUMCVE-2011-1404
Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, ... Read more
Affected Products : mahara- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2011-1502
Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE)... Read more
Affected Products : liferay_portal- Published: May. 07, 2011
- Modified: Apr. 11, 2025
-
4.0
MEDIUMCVE-2009-1055
Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors related to SOAP and XML requests.... Read more
Affected Products : cms- Published: Mar. 24, 2009
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2006-6565
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CV... Read more
Affected Products : filezilla_server- Published: Dec. 15, 2006
- Modified: Apr. 09, 2025
-
4.0
MEDIUMCVE-2015-3187
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has... Read more
- Published: Aug. 12, 2015
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2011-1008
Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demon... Read more
- Published: Feb. 28, 2011
- Modified: Apr. 11, 2025