Show filters
67 Total Results
Displaying 51-60 of 67
Sort by:
Attacker Value
Unknown
CVE-2014-9502
Disclosure Date: February 01, 2018 (last updated November 26, 2024)
Multiple cross-site request forgery (CSRF) vulnerabilities in unspecified sub modules in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allow remote attackers to hijack the authentication of unknown victims via vectors related to menu callbacks.
0
Attacker Value
Unknown
CVE-2017-17840
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
An issue was discovered in Open-iSCSI through 2.0.875. A local attacker can cause the iscsiuio server to abort or potentially execute code by sending messages with incorrect lengths, which (due to lack of checking) can lead to buffer overflows, and result in aborts (with overflow checking enabled) or code execution. The process_iscsid_broadcast function in iscsiuio/src/unix/iscsid_ipc.c does not validate the payload length before a write operation.
0
Attacker Value
Unknown
CVE-2015-3649
Disclosure Date: August 18, 2017 (last updated November 26, 2024)
The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing "openuri-" followed by a crafted UID, and putting Ruby code in said directory once a meta file is created.
0
Attacker Value
Unknown
CVE-2015-0299
Disclosure Date: September 29, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Open Source Point of Sale 2.3.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-4389
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission.
0
Attacker Value
Unknown
CVE-2015-2950
Disclosure Date: June 05, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the Brandon Bowles Open Explorer application before 0.254 Beta for Android allows remote attackers to write to arbitrary files via a crafted filename.
0
Attacker Value
Unknown
CVE-2014-8736
Disclosure Date: November 12, 2014 (last updated October 05, 2023)
The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been removed from a node by leveraging a previous revision of the node.
0
Attacker Value
Unknown
CVE-2014-6234
Disclosure Date: September 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Open Graph protocol (jh_opengraphprotocol) extension before 1.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-5035
Disclosure Date: September 05, 2013 (last updated October 05, 2023)
Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.
0
Attacker Value
Unknown
CVE-2012-1027
Disclosure Date: February 08, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the message parameter to register/account-closed.
0