Unknown · CVSS Not scored
Cross-site scripting vulnerability (XSS) in the Quick Tabs module 6.x-2.x before 6.x-2.1, 6.x-3.x before 6.x-3.1, and 7.x-3.x before 7.x-3.3 for Drupal.
Published Nov 21, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka "CFormElement Use After Free Vulnerability."
Published Nov 14, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
Published Nov 12, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Integer overflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Overflow Vulnerability."
Published Nov 14, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Integer underflow in Windows Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted briefcase, aka "Windows Briefcase Integer Underflow Vulnerability."
Published Nov 14, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Pidgin 2.10.0 uses DBUS for certain cleartext communication, which allows local users to obtain sensitive information via a dbus session monitor.
Published Nov 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
Published Nov 23, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle before 2.2.2: Overview report allows users to see hidden courses
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle before 2.2.2 has users' private files included in course backups
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions
Published Nov 12, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Remote Login Service (RLS) 1.0.0 does not properly clear account information when switching users, which might allow physically proximate users to obtain login credentials.
Published Nov 24, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp before 2.1.2 and before 2.5 Beta 2 allow remote attackers to inject arbitrary web script or HTML via the (1) content parameter to includes/ajax.php or (2) body parameter to includes/error.php.
Published Nov 21, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Unity integration extension (unity-firefox-extension) before 2.4.1 for Firefox does not properly handle callbacks, which allows remote attackers to cause a denial of service (Firefox crash) and possibly execute arbitrary code via a crafted request.
Published Nov 24, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
PyXML: Hash table collisions CPU usage Denial of Service
Published Nov 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
surf: cookie jar has read access from other local user
Published Nov 19, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities
Published Nov 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
uzbl: Information disclosure via world-readable cookies storage file
Published Nov 19, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
RESTEasy before 2.3.1 allows remote attackers to read arbitrary files via an external entity reference in a DOM document, aka an XML external entity (XXE) injection attack.
Published Nov 23, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
gnusound 0.7.5 has format string issue
Published Nov 19, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augnew file.
Published Nov 23, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the (1) .augsave or (2) destination file when using the backup save option, or (3) .augnew file when using the newfile save option.
Published Nov 23, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003.
Published Nov 26, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
Published Nov 7, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Double free vulnerability in the Free_All_Memory function in jpeg/dectile.c in libfpx before 1.3.1-1, as used in the FlashPix PlugIn 4.2.2.0 for IrfanView, allows remote attackers to cause a denial of service (crash) via a crafted FPX image.
Published Nov 2, 2012 · Updated Aug 6, 2024
Unknown · CVSS Not scored
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
Published Nov 7, 2019 · Updated Aug 6, 2024