CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. |
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories. |
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees |
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass |
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service. |
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. |
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request. |
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. |
libuser has information disclosure when moving user's home directory |
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees. |
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value. |
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper. |
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified. |
Moodle before 2.2.2 has users' private files included in course backups |
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to |
ABRT might allow attackers to obtain sensitive information from crash reports. |
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. |
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. |
A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could allow a local user to crash the system, causing a denial of service. |