Lucene search

K

9532, 2591 Security Vulnerabilities

ubuntucve
ubuntucve

CVE-2015-3144

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by...

5.4AI Score

0.065EPSS

2015-04-22 12:00 AM
12
wpvulndb
wpvulndb

Digital Store < 1.3.3 - Unspecified XSS

The digital-store WordPress theme was affected by an Unspecified XSS security...

2AI Score

0.001EPSS

4.3CVSS

2015-04-20 12:00 AM
14
nvd
nvd

CVE-2012-2591

Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an...

5.8AI Score

0.007EPSS

2014-06-20 02:55 PM
cve
cve

CVE-2012-2591

Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an...

5.9AI Score

0.007EPSS

2014-06-20 02:55 PM
25
prion
prion

Cross site scripting

Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an...

6.1AI Score

0.007EPSS

2014-06-20 02:55 PM
1
cvelist
cvelist

CVE-2012-2591

Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an...

5.8AI Score

0.007EPSS

2014-06-20 02:00 PM
nvd
nvd

CVE-2014-2591

Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect RPATH...

6.5AI Score

0.001EPSS

2014-05-14 12:55 AM
5
cve
cve

CVE-2014-2591

Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect RPATH...

6.7AI Score

0.001EPSS

2014-05-14 12:55 AM
22
prion
prion

Design/Logic Flaw

Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect RPATH...

7AI Score

0.001EPSS

2014-05-14 12:55 AM
5
cvelist
cvelist

CVE-2014-2591

Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect RPATH...

6.5AI Score

0.001EPSS

2014-05-14 12:00 AM
attackerkb
attackerkb

CVE-2014-2591

Untrusted search path vulnerability in BMC Patrol for AIX 3.9.00 allows local users to gain privileges via a crafted library, related to an incorrect RPATH setting. Recent assessments: timb-machine at March 05, 2021 12:48am UTC reported:...

5.1AI Score

0.001EPSS

6.9CVSS

2014-05-14 12:00 AM
3
packetstorm

-0.1AI Score

0.001EPSS

2014-04-14 12:00 AM
30
openvas
openvas

Debian: Security Advisory (DSA-2591-1)

The remote host is missing an update for the...

9.1CVSS

7.1AI Score

0.01EPSS

2013-09-18 12:00 AM
3
openvas
openvas

Debian Security Advisory DSA 2591-1 (mahara - several vulnerabilities)

Multiple security issues have been found in Mahara, an electronic portfolio, weblog, and resume builder, which can result in cross-site scripting, clickjacking or arbitrary file...

0.2AI Score

0.01EPSS

2013-09-18 12:00 AM
4
securityvulns
securityvulns

[SECURITY] [DSA 2591-1] mahara security update

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Debian Security Advisory DSA-2591-1 [email protected] http://www.debian.org/security/ Moritz Muehlenhoff December 27, 2012 http://www.debian.org/security/faq Package : mahara...

2.1AI Score

0.01EPSS

2013-01-02 12:00 AM
14
debian
debian

[SECURITY] [DSA 2591-1] mahara security update

Debian Security Advisory DSA-2591-1 [email protected] http://www.debian.org/security/ Moritz Muehlenhoff December 27, 2012 http://www.debian.org/security/faq Package : mahara Vulnerability : several Problem type : remote...

9.1CVSS

9.7AI Score

0.01EPSS

2012-12-28 01:08 AM
8
nessus
nessus

Debian DSA-2591-1 : mahara - several vulnerabilities

Multiple security issues have been found in Mahara, an electronic portfolio, weblog, and resume builder, which can result in cross-site scripting, clickjacking or arbitrary file...

9.1CVSS

AI Score

0.01EPSS

2012-12-28 12:00 AM
15
osv
osv

mahara - several

Multiple security issues have been found in Mahara, an electronic portfolio, weblog, and resume builder, which can result in cross-site scripting, clickjacking or arbitrary file execution. For the stable distribution (squeeze), these problems have been fixed in version 1.2.6-2+squeeze6. For the...

3.5AI Score

2012-12-27 12:00 AM
7
nvd
nvd

CVE-2012-6037

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in error messages in the...

8.2AI Score

0.01EPSS

2012-11-24 08:55 PM
cve
cve

CVE-2012-6037

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in error messages in the...

7.8AI Score

0.01EPSS

2012-11-24 08:55 PM
24
cve
cve

CVE-2012-2243

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml extension, which is rendered inline as script. NOTE: this can be leveraged with CVE-2012-2244 to...

7.8AI Score

0.01EPSS

2012-11-24 08:55 PM
30
nvd
nvd

CVE-2012-2247

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a crafted SVG...

7.6AI Score

0.002EPSS

2012-11-24 08:55 PM
cve
cve

CVE-2012-2253

Cross-site scripting (XSS) vulnerability in group/members.php in Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the query...

7.4AI Score

0.002EPSS

2012-11-24 08:55 PM
23
cve
cve

CVE-2012-2239

Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading...

9.1CVSS

9.2AI Score

0.002EPSS

2012-11-24 08:55 PM
36
cve
cve

CVE-2012-2244

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authentication by leveraging...

9.1AI Score

0.01EPSS

2012-11-24 08:55 PM
25
nvd
nvd

CVE-2012-2246

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via...

9.3AI Score

0.006EPSS

2012-11-24 08:55 PM
nvd
nvd

CVE-2012-2239

Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading...

9.1CVSS

9.4AI Score

0.002EPSS

2012-11-24 08:55 PM
nvd
nvd

CVE-2012-2243

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml extension, which is rendered inline as script. NOTE: this can be leveraged with CVE-2012-2244 to...

8.1AI Score

0.01EPSS

2012-11-24 08:55 PM
cve
cve

CVE-2012-2246

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via...

9.1AI Score

0.006EPSS

2012-11-24 08:55 PM
24
cve
cve

CVE-2012-2247

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a crafted SVG...

7.2AI Score

0.002EPSS

2012-11-24 08:55 PM
25
nvd
nvd

CVE-2012-2253

Cross-site scripting (XSS) vulnerability in group/members.php in Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the query...

7.8AI Score

0.002EPSS

2012-11-24 08:55 PM
nvd
nvd

CVE-2012-2244

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authentication by leveraging...

9.3AI Score

0.01EPSS

2012-11-24 08:55 PM
prion
prion

Authentication flaw

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authentication by leveraging...

7.2AI Score

0.01EPSS

2012-11-24 08:55 PM
5
prion
prion

Cross site request forgery (csrf)

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via...

7.3AI Score

0.006EPSS

2012-11-24 08:55 PM
2
prion
prion

Cross site scripting

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a crafted SVG...

6AI Score

0.002EPSS

2012-11-24 08:55 PM
4
prion
prion

Cross site scripting

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in error messages in the...

5.9AI Score

0.01EPSS

2012-11-24 08:55 PM
2
prion
prion

Cross site scripting

Cross-site scripting (XSS) vulnerability in group/members.php in Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the query...

6.1AI Score

0.002EPSS

2012-11-24 08:55 PM
prion
prion

Cross site scripting

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml extension, which is rendered inline as script. NOTE: this can be leveraged with CVE-2012-2244 to...

6.5AI Score

0.01EPSS

2012-11-24 08:55 PM
5
prion
prion

Xxe

Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading...

9.1CVSS

7.5AI Score

0.002EPSS

2012-11-24 08:55 PM
2
cvelist
cvelist

CVE-2012-2246

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via...

9.3AI Score

0.006EPSS

2012-11-24 08:00 PM
cvelist
cvelist

CVE-2012-2239

Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading...

9.4AI Score

0.002EPSS

2012-11-24 08:00 PM
cvelist
cvelist

CVE-2012-2253

Cross-site scripting (XSS) vulnerability in group/members.php in Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the query...

7.7AI Score

0.002EPSS

2012-11-24 08:00 PM
cvelist
cvelist

CVE-2012-6037

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in error messages in the...

8.2AI Score

0.01EPSS

2012-11-24 08:00 PM
cvelist
cvelist

CVE-2012-2247

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a crafted SVG...

7.6AI Score

0.002EPSS

2012-11-24 08:00 PM
cvelist
cvelist

CVE-2012-2244

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authentication by leveraging...

9.3AI Score

0.01EPSS

2012-11-24 08:00 PM
1
cvelist
cvelist

CVE-2012-2243

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml extension, which is rendered inline as script. NOTE: this can be leveraged with CVE-2012-2244 to...

8.1AI Score

0.01EPSS

2012-11-24 08:00 PM
packetstorm

AI Score

0.007EPSS

2012-08-08 12:00 AM
12
nessus
nessus

Scientific Linux Security Update : gcc on SL3.x i386/x86_64

Jürgen Weigert discovered a directory traversal flaw in fastjar. An attacker could create a malicious JAR file which, if unpacked using fastjar, could write to any files the victim had write access to....

0.1AI Score

0.01EPSS

2012-08-01 12:00 AM
10
openvas
openvas

Fedora Update for postgresql FEDORA-2012-2591

The remote host is missing an update for...

6.7AI Score

0.009EPSS

2012-04-02 12:00 AM
4
Total number of security vulnerabilities459