Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2015-3231

Disclosure Date: June 22, 2015 (last updated October 05, 2023)
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
0
Attacker Value
Unknown

CVE-2015-3234

Disclosure Date: June 22, 2015 (last updated October 05, 2023)
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by the Verisign, LiveJournal, and StackExchange providers.
0
Attacker Value
Unknown

CVE-2014-5267

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
0
Attacker Value
Unknown

CVE-2014-5266

Disclosure Date: August 18, 2014 (last updated October 05, 2023)
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.
0
Attacker Value
Unknown

CVE-2014-5265

Disclosure Date: August 18, 2014 (last updated October 05, 2023)
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown

CVE-2014-5021

Disclosure Date: July 22, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.
0
Attacker Value
Unknown

CVE-2014-5022

Disclosure Date: July 22, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.
0
Attacker Value
Unknown

CVE-2014-5020

Disclosure Date: July 22, 2014 (last updated October 05, 2023)
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.
0
Attacker Value
Unknown

CVE-2014-5019

Disclosure Date: July 22, 2014 (last updated October 05, 2023)
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.
0
Attacker Value
Unknown

CVE-2014-1476

Disclosure Date: January 24, 2014 (last updated October 05, 2023)
The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.
0