CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2015-3148

    Last Modified: 12 Apr 2025

    cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.

    Published: 22 Apr 2015
    7.1
    High

    CVE-2015-3150

    Last Modified: 21 Nov 2024

    abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.

    Published: 22 Apr 2015
    3.5
    Low

    CVE-2015-3384

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Bank Account Listing Page in the Commerce Balanced Payments module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3392

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Ajax Timeline module before 7.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3385

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Taxonomy Path module before 7.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the "Link to path" field formatter.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3393

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Commerce WeDeal module before 7.x-1.3 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3383

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Node basket module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 21 Apr 2015
    4.9
    Medium

    CVE-2015-3378

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal, when the Views UI submodule is enabled, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to the break lock page for edited views.

    Published: 21 Apr 2015
    4
    Medium

    CVE-2015-3379

    Last Modified: 12 Apr 2025

    The Views module before 6.x-2.18, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to the default views configurations, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3380

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Feature Set module for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable or (2) disable a module via unspecified vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3381

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Node basket module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3382

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Node basket module for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add or (2) remove nodes from a basket via unspecified vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3386

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Node Access Product module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3387

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy Tools module before 7.x-1.4 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via a (1) node or (2) taxonomy term title.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3388

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Commerce Balanced Payments module for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete the user's configured bank accounts via unspecified vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3389

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Download counts report page in the Public Download Count module (pubdlcnt) 7.x-1.x-dev and earlier for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3390

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Facebook Album Fetcher module for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Apr 2015
    5
    Medium

    CVE-2015-3391

    Last Modified: 12 Apr 2025

    The Path Breadcrumbs module before 7.x-3.2 for Drupal allows remote attackers to bypass intended access restrictions and obtain sensitive node titles by reading a 403 Not Found page.

    Published: 21 Apr 2015
    10
    Critical

    CVE-2015-0135

    Last Modified: 12 Apr 2025

    IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (integer truncation and application crash) via a crafted GIF image, aka SPR KLYH9T7NT9.

    Published: 21 Apr 2015
    6.5
    Medium

    CVE-2015-3345

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the PHPlist Integration Module before 6.x-1.7 for Drupal allows remote administrators to execute arbitrary SQL commands via unspecified vectors, related to the "phpList database."

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3349

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Htaccess module before 7.x-2.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) deploy or (2) delete an .htaccess file via unspecified vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3357

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Wishlist module before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "access wishlists" permission to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a log message.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3366

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Alfresco module before 6.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete an alfresco node via unspecified vectors.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3367

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Patterns module before 7.x-2.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) restore, (2) publish, or (3) unpublish a pattern via unspecified vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3369

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Taxonews module before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a term name in a block.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3374

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Corner module for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable or (2) disable corners via unspecified vectors.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3342

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Ubercart Currency Conversion module before 6.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination query parameter.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3350

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Todo Filter module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that toggle a task via unspecified vectors.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3358

    Last Modified: 12 Apr 2025

    Multiple open redirect vulnerabilities in the Tadaa! module before 7.x-1.4 for Drupal allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a destination parameter, related to callbacks that (1) enable and disable modules or (2) change variables.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3368

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administration user interface in the Classified Ads module before 6.x-3.1 and 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a category name.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3375

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Shibboleth Authentication module before 6.x-4.1 and 7.x-4.x before 7.x-4.1 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete user role matching rules via unspecified vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3365

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the nodeauthor module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a Profile2 field in a provided block.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3348

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Cloudwords for Multilingual Drupal module before 7.x-2.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3343

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the OPAC module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims for requests that remove a mapping via unknown vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3344

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Course module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.

    Published: 21 Apr 2015
    7.5
    High

    CVE-2015-3346

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the WikiWiki module before 6.x-1.2 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3347

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Cloudwords for Multilingual Drupal module before 7.x-2.3 for Drupal allows remote attackers to hijack the authentication of unspecified victims via an unknown menu callback.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3351

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Log Watcher module before 6.x-1.2 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable, (2) disable, or (3) delete a report via unspecified vectors.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3352

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Jammer module before 6.x-1.8 and 7.x-1.x before 7.x-1.4 for Drupal allow remote attackers to hijack the authentication of administrators for requests that delete a setting for (1) hidden form elements or (2) status messages via unspecified vectors, related to "report administration."

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3353

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Field Display Label module before 7.x-1.3 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the alternate field label in content types settings.

    Published: 21 Apr 2015
    5.8
    Medium

    CVE-2015-3354

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Wishlist module before 6.x-2.7 and 7.x-2.x before 7.x-2.7 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that delete wishlist purchase intentions via unspecified vectors.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3355

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Batch Jobs module before 7.x-1.2 for Drupal allow remote attackers to hijack the authentication of certain users for requests that (1) delete a batch job record or (2) execute a task via unspecified vectors.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3356

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Tadaa! module before 7.x-1.4 for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) enable or (2) disable modules or (3) change variables via unspecified vectors.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3359

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Room Reservations module before 7.x-1.1 for Drupal allow remote authenticated users with the "Administer the room reservations system" permission to inject arbitrary web script or HTML via the (1) node title of a "Room Reservations Category" or (2) body of a "Room Reservations Room" node.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3360

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Term Merge module before 7.x-1.2 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Apr 2015
    2.1
    Low

    CVE-2015-3361

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Linkit module before 7.x-2.7 and 7.x-3.x before 7.x-3.3 for Drupal, when the node search plugin is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a node title.

    Published: 21 Apr 2015
    3.5
    Low

    CVE-2015-3362

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Video module before 7.x-2.11 for Drupal, when using the video WYSIWYG plugin, allows remote authenticated users to inject arbitrary web script or HTML via a node title.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3363

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Contact Form Fields module before 6.x-2.3 for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete fields via unspecified vectors.

    Published: 21 Apr 2015
    4.3
    Medium

    CVE-2015-3364

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Content Analysis module before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a log message.

    Published: 21 Apr 2015
    6.8
    Medium

    CVE-2015-3370

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to hijack the authentication of users with the "node_invite_can_manage_invite" permission for requests that re-enable node invitations via unspecified vectors.

    Published: 21 Apr 2015