Vulnerability index

Browse CVEs

252 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.1 CVE-2006-4120 Cross-site scripting (XSS) vulnerability in the Recipe module (recipe.module) before 1.54 for Drupal 4.6 and earlier allows remote attackers to injec… Drupal after 4.6 Fix from $1,6002006-08-14 HIGH 7.5 CVE-2006-4107 SQL injection vulnerability in the Job Search module (job.module) 4.6 before revision 1.3.2.1 in Drupal allows remote attackers to execute arbitrary … Job Search Patch available Fix from $1,9502006-08-14 HIGH 7.5 CVE-2006-4108 SQL injection vulnerability in Bibliography (biblio.module) 4.6 before revision 1.1.1.1.4.11 and 4.7 before revision 1.13.2.5 for Drupal allows remot… Bibliography Module after 4.7_rev1.13.2.4 Fix from $1,9502006-08-14 HIGH 7.5 CVE-2006-3473 CRLF injection vulnerability in form_mail Drupal Module before 1.8.2.2 allows remote attackers to inject e-mail headers, which facilitates sending sp… Form Mail Module after 1.8.2.1 Fix from $1,9502006-07-10 HIGH 7.5 CVE-2006-2831 Drupal 4.6.x before 4.6.8 and 4.7.x before 4.7.2, when running under certain Apache configurations such as when FileInfo overrides are disabled withi… Drupal Patch available Fix from $1,9502006-06-06 HIGH 7.5 CVE-2006-2742 SQL injection vulnerability in Drupal 4.6.x before 4.6.7 and 4.7.0 allows remote attackers to execute arbitrary SQL commands via the (1) count and (2… Drupal Patch available Fix from $1,9502006-06-01 MEDIUM 5.1 CVE-2006-2743EPSS 11% Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remo… Drupal Patch available Fix from $1,6002006-06-01 MEDIUM 5.1 CVE-2006-1228 Session fixation vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to gain privileges by tricking a user to c… Drupal Patch available Fix from $1,6002006-03-14 MEDIUM 5.0 CVE-2006-1225 CRLF injection vulnerability in Drupal 4.5.x before 4.5.8 and 4.6.x before 4.5.8 allows remote attackers to inject headers of outgoing e-mail message… Drupal Patch available Fix from $1,6002006-03-14 MEDIUM 6.4 CVE-2005-3974 Drupal 4.5.0 through 4.5.5 and 4.6.0 through 4.6.3, when running on PHP5, does not correctly enforce user privileges, which allows remote attackers t… Drupal Patch available Fix from $1,6002005-12-03 MEDIUM 5.0 CVE-2005-2106 Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or p… Drupal Patch available Fix from $1,6002005-07-05 HIGH 7.5 CVE-2005-1871 Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain pri… Drupal Mitigation only Fix from $1,9502005-06-09