Search CVE reports


Toggle filters

351 – 360 of 526 results


CVE-2015-2575

Medium priority
Vulnerable

Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Connector/J.

1 affected package

mysql-connector-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mysql-connector-java Not in release Not in release Not in release Not in release Not affected
Show less packages

CVE-2014-3684

Medium priority

Some fixes available 2 of 4

The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted...

1 affected package

torque

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torque Not in release
Show less packages

CVE-2014-3558

Medium priority
Ignored

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute...

1 affected package

libhibernate-validator-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhibernate-validator-java Not affected
Show less packages

CVE-2014-6029

Medium priority
Ignored

TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.

1 affected package

torrentflux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torrentflux Not in release
Show less packages

CVE-2014-6028

Medium priority
Ignored

TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.

1 affected package

torrentflux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torrentflux Not in release
Show less packages

CVE-2014-5191

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

ckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected
Show less packages

CVE-2014-5117

Medium priority

Some fixes available 2 of 4

Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2014-4722

Medium priority
Vulnerable

Multiple cross-site scripting (XSS) vulnerabilities in the OCS Reports Web Interface in OCS Inventory NG allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not in release Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2014-4037

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitrary web script or HTML via an...

1 affected package

fckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fckeditor Not in release
Show less packages

CVE-2014-3004

Medium priority
Vulnerable

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

1 affected package

castor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
castor Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages