NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25847  CVE-2015-4389  The Open Graph Importer (og_tag_importer) 7.x-1.x for Drupal does not properly check the create permission for content types created during import, which allows remote authenticated users to bypass intended restrictions by leveraging the "import og_tag_importer" permission.    Medium  2017-01-19  2016-06-09  View
25848  CVE-2015-4390  Multiple cross-site request forgery (CSRF) vulnerabilities in the User Import module 6.x-4.x before 6.x-4.4 and 7.x-2.x before 7.x-2.3 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) continue or (2) delete an ongoing import via unspecified vectors.    6.8  Medium  2017-01-19  2016-06-09  View
25849  CVE-2015-4391  Cross-site request forgery (CSRF) vulnerability in the CiviCRM private report module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of users for requests that delete reports via unspecified vectors.    6.8  Medium  2017-01-19  2016-06-09  View
25850  CVE-2015-4392  Cross-site scripting (XSS) vulnerability in the Display Suite module 7.x-2.7 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to field display settings.    3.5  Low  2017-01-19  2015-06-26  View
25851  CVE-2015-4393  The resource/endpoint for uploading files in the Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote authenticated users with the "Save file information" permission to execute arbitrary code via a crafted filename.    Medium  2017-01-19  2016-06-09  View

Page 14484 of 17672, showing 5 records out of 88360 total, starting on record 72416, ending on 72420

Actions