Search Results (9984 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2012-6685 2 Nokogiri, Redhat 9 Nokogiri, Cloudforms Management Engine, Cloudforms Managementengine and 6 more 2024-11-21 7.5 High
Nokogiri before 1.5.4 is vulnerable to XXE attacks
CVE-2012-5686 1 Zpanelcp 1 Zpanel 2024-11-21 9.8 Critical
ZPanel 10.0.1 has insufficient entropy for its password reset process.
CVE-2012-5618 1 Ushahidi 1 Ushahidi 2024-11-21 9.8 Critical
Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens.
CVE-2012-5521 3 Debian, Quagga, Redhat 3 Debian Linux, Quagga, Enterprise Linux 2024-11-21 6.5 Medium
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
CVE-2012-2979 1 Freebsd 1 Name Server Daemon 2024-11-21 7.5 High
FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server.
CVE-2012-2656 1 Talend 1 Restlet 2024-11-21 7.5 High
An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive information.
CVE-2012-1102 1 Xml\ 1 \ 2024-11-21 7.5 High
It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted sources. This may allow attackers to gain read access to otherwise protected resources, depending on how the library is used.
CVE-2011-3600 1 Apache 1 Ofbiz 2024-11-21 7.5 High
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.
CVE-2011-3596 2 Debian, Polipo Project 2 Debian Linux, Polipo 2024-11-21 7.5 High
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
CVE-2011-3151 1 Canonical 1 Selinux 2024-11-21 N/A
The Ubuntu SELinux initscript before version 1:0.10 used touch to create a lockfile in a world-writable directory. If the OS kernel does not have symlink protections then an attacker can cause a zero byte file to be allocated on any writable filesystem.
CVE-2010-4266 1 Vanillaforums 1 Vanilla Forums 2024-11-21 6.1 Medium
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
CVE-2010-3669 1 Typo3 1 Typo3 2024-11-21 5.4 Medium
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
CVE-2010-3661 1 Typo3 1 Typo3 2024-11-21 6.1 Medium
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
CVE-2010-3300 1 Owasp 1 Enterprise Security Api For Java 2024-11-21 5.9 Medium
It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.
CVE-2010-2471 2 Debian, Drupal 2 Debian Linux, Drupal 2024-11-21 6.1 Medium
Drupal versions 5.x and 6.x has open redirection
CVE-2009-5042 2 Debian, Python-docutils Project 2 Debian Linux, Python-docutils 2024-11-21 9.1 Critical
python-docutils allows insecure usage of temporary files
CVE-2009-5025 1 Pyforum Project 1 Pyforum 2024-11-21 7.5 High
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.
CVE-2009-20001 1 Mantisbt 1 Mantisbt 2024-11-21 8.1 High
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.
CVE-2008-7291 2 Debian, Gri Project 2 Debian Linux, Gri 2024-11-21 9.8 Critical
gri before 2.12.18 generates temporary files in an insecure way.
CVE-2008-2544 1 Linux 1 Linux Kernel 2024-11-21 5.5 Medium
Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot environment and gain write access to files, he would never have otherwise.