Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-7227 | 1 Fieldable Panels Panes Project | 1 Fieldable Panels Panes | 2015-09-21 | 3.5 LOW | N/A |
The Fieldable Panels Panes module 7.x-1.x before 7.x-1.7 for Drupal does not properly check permissions to edit Fieldable Panels Panes entities, which allows remote authenticated users to edit panes by leveraging permissions to edit panels. | |||||
CVE-2015-7229 | 1 Twitter Project | 1 Twitter | 2015-09-21 | 3.5 LOW | N/A |
The Twitter module 6.x-5.x before 6.x-5.2, 7.x-5.x before 7.x-5.9, and 7.x-6.x before 7.x-6.0 for Drupal does not properly check access permissions, which allows remote authenticated users to post tweets to arbitrary accounts by leveraging the (1) "post to twitter" permission or change the options for arbitrary attached accounts by leveraging the (2) "add twitter accounts" or (3) "add authenticated twitter accounts" permission. | |||||
CVE-2015-7230 | 1 Workbench Email Project | 1 Workbench Email | 2015-09-21 | 3.5 LOW | N/A |
The Workbench Email module 7.x-3.x before 7.x-3.4 for Drupal allows remote authenticated users with certain permissions to bypass node and field validation by saving a node. | |||||
CVE-2014-9476 | 1 Mediawiki | 1 Mediawiki | 2015-09-17 | 5.0 MEDIUM | N/A |
MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/." | |||||
CVE-2015-5498 | 1 Shipwire Api Project | 1 Shipwire Api | 2015-09-03 | 5.0 MEDIUM | N/A |
The Shipwire API module 7.x-1.x before 7.x-1.03 for Drupal does not check the view permission for the shipments overview (admin/shipwire/shipments), which allows remote attackers to obtain sensitive information via a request to the page. | |||||
CVE-2011-2687 | 1 Drupal | 1 Drupal | 2015-09-03 | 7.5 HIGH | N/A |
Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks a JOIN clause for the node table. | |||||
CVE-2015-6520 | 1 Ippusbxd Project | 1 Ippusbxd | 2015-09-02 | 7.5 HIGH | N/A |
IPPUSBXD before 1.22 listens on all interfaces, which allows remote attackers to obtain access to USB connected printers via a direct request. | |||||
CVE-2015-6745 | 1 Basware | 1 Banking | 2015-08-31 | 4.6 MEDIUM | N/A |
Basware Banking (Maksuliikenne) 8.90.07.X relies on the client to enforce account locking, which allows local users to bypass that security mechanism by deleting the entry from the locking table. NOTE: this identifier was SPLIT from CVE-2015-0942 per ADT2 and ADT3 due to different vulnerability type and different affected versions. NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-6744. | |||||
CVE-2015-3158 | 1 Picketlink | 1 Picketlink | 2015-08-27 | 4.0 MEDIUM | N/A |
The invokeNextValve function in identity/federation/bindings/tomcat/idp/AbstractIDPValve.java in PicketLink before 2.8.0.Beta1 does not properly check role based authorization, which allows remote authenticated users to gain access to restricted application resources via a (1) direct request or (2) request through an SP initiated flow. | |||||
CVE-2015-5402 | 1 Hp | 2 Matrix Operating Environment, Systems Insight Manager | 2015-08-27 | 7.2 HIGH | N/A |
HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows local users to gain privileges, and consequently obtain sensitive information, modify data, or cause a denial of service, via unspecified vectors. | |||||
CVE-2015-5961 | 1 Mozilla | 1 Firefox Os | 2015-08-21 | 3.3 LOW | N/A |
The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server. | |||||
CVE-2015-5499 | 1 Navigate Project | 1 Navigate | 2015-08-19 | 4.0 MEDIUM | N/A |
The Navigate module for Drupal does not properly check permissions, which allows remote authenticated users to modify custom widgets and create widget database records by leveraging the "navigate view" permission. | |||||
CVE-2015-5493 | 1 Entityform Block Project | 1 Entityform Block | 2015-08-19 | 5.0 MEDIUM | N/A |
The Entityform Block module 7.x-1.x before 7.x-1.3 for Drupal does not properly check permissions when a form is locked to a role, which allows remote attackers to obtain access to certain entityforms via unspecified vectors. | |||||
CVE-2014-2541 | 1 Tibco | 3 Messaging Appliance, Rendezvous, Substantiation Es | 2015-08-11 | 5.0 MEDIUM | N/A |
The Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO Rendezvous before 8.4.2, Messaging Appliance before 8.7.1, and Substation ES before 2.8.1 do not properly implement access control, which allows remote attackers to obtain sensitive information or modify transmitted information via unspecified vectors. | |||||
CVE-2015-2871 | 1 Chiyu | 1 Bf-660c | 2015-08-10 | 7.5 HIGH | N/A |
Chiyu BF-660C fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify communication configuration settings via a request to net.htm, a different vulnerability than CVE-2015-5618. | |||||
CVE-2015-5618 | 1 Chiyutw | 2 Bf-630, Bf-630w | 2015-08-03 | 7.5 HIGH | N/A |
Chiyu BF-630 and BF-630W fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify (a) Voice Time Set configuration settings via a request to voice.htm or (b) UniFinger configuration settings via a request to bf.htm, a different vulnerability than CVE-2015-2871. | |||||
CVE-2015-4287 | 1 Cisco | 1 Firepower Extensible Operating System | 2015-07-29 | 5.0 MEDIUM | N/A |
Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and obtain sensitive device information by visiting an unspecified web page, aka Bug ID CSCuu82230. | |||||
CVE-2014-2102 | 1 Cisco | 1 Unified Contact Center Express Editor Software | 2015-07-29 | 4.0 MEDIUM | N/A |
Cisco Unified Contact Center Express (Unified CCX) does not properly restrict the content of the CCMConfig page, which allows remote authenticated users to obtain sensitive information by examining this content, aka Bug ID CSCum95575. | |||||
CVE-2005-4854 | 1 Ez | 1 Ez Publish | 2015-07-28 | 5.0 MEDIUM | N/A |
eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated users to obtain sensitive information about changes to content in arbitrary folders. | |||||
CVE-2005-4853 | 1 Ez | 1 Ez Publish | 2015-07-28 | 9.4 HIGH | N/A |
The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to a posting's owner, which allows remote authenticated users to edit arbitrary postings. |