VYPR

CVEs

387,025 total · page 6639 of 7,741

  • CVE-2013-1859Mar 27, 2013
    risk 0.00cvss —epss 0.03

    The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to read and edit configuration options via unspecified vectors.

  • CVE-2013-1787Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Simple Corporate theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-1786Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Company theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-1785Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Premium Responsive theme before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-1784Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Clean Theme before 7.x-1.3 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-1783Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the 3 slide gallery in page--front.tpl.php in the Business theme before 7.x-1.8 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-1782Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Responsive Blog Theme 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.

  • CVE-2013-1781Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Professional theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-1780Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Best Responsive Theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.

  • CVE-2013-1779Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Fresh theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-1778Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Creative Theme 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via vectors related to social icons.

  • CVE-2013-0325Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Varnish module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta2 for Drupal allow remote attackers to inject arbitrary web script or HTML via crafted a (1) Watchdog message or (2) admin setting.

  • CVE-2013-0324Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Rendered links formatter in the Menu Reference module 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with the "Administer menus and menu items" permission to inject arbitrary web script or HTML via the menu…

  • CVE-2013-0323Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-1.x before 7.x-1.7 and 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the author field.

  • CVE-2013-0322Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Views in the Ubercart module 7.x-3.x before 7.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

  • CVE-2013-0321Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Views in the Ubercart Views (uc_views) module 6.x before 6.x-3.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the full name field.

  • CVE-2013-0320Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the Taxonomy Manager (taxonomy_manager) module 6.x-2.x before 6.x-2.2 and 7.x-1.x before 7.x-1.0-rc1 for Drupal allows remote attackers to hijack the authentication of users with 'administer taxonomy' permissions via unspecified…

  • CVE-2013-0319Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Yandex.Metrics module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the Yandex.Metrica service data.

  • CVE-2013-0318Mar 27, 2013
    risk 0.00cvss —epss 0.02

    The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions via unspecified vectors.

  • CVE-2013-0317Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Manager Change for Organic Groups (og_manager_change) module 7.x-2.x before 7.x-2.1 for Drupal might allow remote attackers to inject arbitrary web script or HTML via the username in the new manager autocomplete field.

  • CVE-2013-0316Mar 27, 2013
    risk 0.00cvss —epss 0.02

    The Image module in Drupal 7.x before 7.20 allows remote attackers to cause a denial of service (CPU and disk space consumption) via a large number of new derivative requests.

  • CVE-2013-0260Mar 27, 2013
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the Drush Debian Packaging module for Drupal allows local users to obtain database credentials via unknown vectors.

  • CVE-2013-0259Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the Boxes module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with administer or edit boxes permissions to inject arbitrary web script or HTML via the subject parameter.

  • CVE-2013-0258Mar 27, 2013
    risk 0.00cvss —epss 0.01

    The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers to bypass authentication for accounts without an associated Google Authenticator token by logging in with the username.

  • CVE-2013-0257Mar 27, 2013
    risk 0.00cvss —epss 0.01

    The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of user email addresses and email fields.

  • CVE-2013-0182Mar 27, 2013
    risk 0.00cvss —epss 0.01

    The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary payments.

  • CVE-2013-0181Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in Views in the Search API (search_api) module 7.x-1.x before 7.x-1.4 for Drupal, when using certain backends and facets, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error…

  • CVE-2013-2300Mar 27, 2013
    risk 0.00cvss —epss 0.01

    The FlickWnn (aka OpenWnn/Flick support) application 2.02 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information via an application that accesses the local filesystem.

  • CVE-2013-0720Mar 27, 2013
    risk 0.00cvss —epss 0.01

    The COBIME application before 0.9.4 for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information via an application that accesses the local filesystem.

  • CVE-2013-0719Mar 27, 2013
    risk 0.00cvss —epss 0.01

    The ArtIME Japanese Input application 1.1.2 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information via an application that accesses the local filesystem.

  • CVE-2013-0718Mar 27, 2013
    risk 0.00cvss —epss 0.01

    The Simeji application 4.8.1 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information via an application that accesses the local filesystem.

  • CVE-2013-0489Mar 27, 2013
    risk 0.00cvss —epss 0.00

    Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote authenticated users to hijack the authentication of administrators.

  • CVE-2013-0488Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-0487Mar 27, 2013
    risk 0.00cvss —epss 0.02

    The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration details, aka SPR KLYH8TNNDN.

  • CVE-2013-0486Mar 27, 2013
    risk 0.00cvss —epss 0.01

    Memory leak in the HTTP server in IBM Domino 8.5.x allows remote attackers to cause a denial of service (memory consumption and daemon crash) via GET requests, aka SPR KLYH92NKZY.

  • CVE-2013-0525Mar 26, 2013
    risk 0.00cvss —epss 0.00

    Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX.

  • CVE-2013-0454Mar 26, 2013
    risk 0.00cvss —epss 0.03

    The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a…

  • CVE-2012-5943Mar 26, 2013
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.

  • CVE-2013-1609HigMar 26, 2013
    risk 0.51cvss 7.8epss 0.00

    Multiple unquoted Windows search path vulnerabilities in the (1) File Collector and (2) File PlaceHolder services in Symantec Enterprise Vault (EV) for File System Archiving before 9.0.4 and 10.x before 10.0.1 allow local users to gain privileges via a Trojan horse program.

  • CVE-2013-1608Mar 26, 2013
    risk 0.00cvss —epss 0.01

    Directory traversal vulnerability in the Management Console on the Symantec NetBackup (NBU) appliance 2.0.x allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2013-1162Mar 26, 2013
    risk 0.00cvss —epss 0.01

    The traffic engineering (TE) processing subsystem in Cisco IOS XR allows remote attackers to cause a denial of service (process restart) via crafted TE packets, aka Bug ID CSCue04000.

  • CVE-2013-1161Mar 26, 2013
    risk 0.00cvss —epss 0.01

    The XML parser in the Cisco Jabber IM application for Android allows remote authenticated users to cause a denial of service (blocked connection) by leveraging an entry on a Buddy list and sending a crafted XMPP presence update message, aka Bug ID CSCue38383.

  • CVE-2013-1836Mar 25, 2013
    risk 0.00cvss —epss 0.02

    Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories, which allows remote authenticated users to read, modify, or delete arbitrary site-wide repositories by leveraging certain read…

  • CVE-2013-1835Mar 25, 2013
    risk 0.00cvss —epss 0.01

    Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated administrators to obtain sensitive information from the external repositories of arbitrary users by leveraging the login_as feature.

  • CVE-2013-1834Mar 25, 2013
    risk 0.00cvss —epss 0.02

    notes/edit.php in Moodle 1.9.x through 1.9.19, 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote authenticated users to reassign notes via a modified (1) userid or (2) courseid field.

  • CVE-2013-1833Mar 25, 2013
    risk 0.00cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allow remote authenticated users to inject arbitrary web script or HTML via a crafted filename.

  • CVE-2013-1832Mar 25, 2013
    risk 0.00cvss —epss 0.01

    repository/webdav/lib.php in Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 includes the WebDAV password in the configuration form, which allows remote authenticated administrators to obtain sensitive information by configuring an…

  • CVE-2013-1831Mar 25, 2013
    risk 0.00cvss —epss 0.01

    lib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the absolute path in an exception message.

  • CVE-2013-1830Mar 25, 2013
    risk 0.00cvss —epss 0.02

    user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated…

  • CVE-2013-1829Mar 25, 2013
    risk 0.00cvss —epss 0.01

    calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role.