Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2013-08-28 CVE-2013-2035 Code Injection vulnerability in Redhat Hawtjni
Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.
local
redhat CWE-94
4.4
2013-08-28 CVE-2013-4274 Cross-Site Scripting vulnerability in Erikwebb Password Policy
Cross-site scripting (XSS) vulnerability in the password_policy_admin_view function in password_policy.admin.inc in the Password Policy module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer policies" permission to inject arbitrary web script or HTML via the "Password Expiration Warning" field to the admin/config/people/password_policy/add page.
network
high complexity
erikwebb drupal CWE-79
2.1
2013-08-28 CVE-2013-4272 Information Exposure vulnerability in Botcha Spam Prevention Project Botcha
The BOTCHA Spam Prevention module 7.x-1.x before 7.x-1.6, 7.x-2.x before 7.x-2.1, and 7.x-3.x before 7.x-3.3 for Drupal, when the debugging level is set to 5 or 6, logs the content of submitted forms, which allows context-dependent users to obtain sensitive information such as usernames and passwords by reading the log file.
4.3
2013-08-28 CVE-2013-4139 Unspecified vulnerability in Stage File Proxy Project Stage File Proxy
The Stage File Proxy module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to cause a denial of service (file operations performance degradation and failure) via a large number of requests.
network
low complexity
stage-file-proxy-project drupal
5.0
2013-08-28 CVE-2013-4138 Cross-Site Scripting vulnerability in Alienwp Hatch
Cross-site scripting (XSS) vulnerability in the Hatch theme 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with the "Administer content," "Create new article," or "Edit any article type content" permission to inject arbitrary web script or HTML via unspecified vectors.
network
high complexity
alienwp drupal CWE-79
2.1
2013-08-28 CVE-2013-2247 Permissions, Privileges, and Access Controls vulnerability in Fast Permissions Administration Project Fast Permission Administration
The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the modal content callback, which allows remote attackers to obtain unspecified access to the permissions edit form.
7.5
2013-08-28 CVE-2013-2197 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Login Security Project Login Security
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal, when using the login delay option, allows remote attackers to cause a denial of service (CPU consumption) via a large number of failed login attempts.
4.3
2013-08-28 CVE-2013-2123 Permissions, Privileges, and Access Controls vulnerability in Node Access User Reference Project Nodeaccess Userreference Module
The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.
5.8
2013-08-28 CVE-2013-3495 Permissions, Privileges, and Access Controls vulnerability in multiple products
The Intel VT-d Interrupt Remapping engine in Xen 3.3.x through 4.3.x allows local guests to cause a denial of service (kernel panic) via a malformed Message Signaled Interrupt (MSI) from a PCI device that is bus mastering capable that triggers a System Error Reporting (SERR) Non-Maskable Interrupt (NMI).
4.7
2013-08-28 CVE-2013-2212 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in XEN
The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GFN range.
5.7