Vulnerabilities > Drupal > Drupal > 6.29

DATE CVE VULNERABILITY TITLE RISK
2014-08-18 CVE-2014-5265 Resource Management Errors vulnerability in multiple products
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
network
low complexity
wordpress drupal debian CWE-399
5.0
2014-07-22 CVE-2014-5021 Cross-Site Scripting vulnerability in Drupal
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.
network
high complexity
drupal CWE-79
2.1
2014-07-22 CVE-2014-5019 Improper Input Validation vulnerability in Drupal
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.
network
low complexity
drupal CWE-20
5.0
2014-04-23 CVE-2014-2983 Information Exposure vulnerability in multiple products
Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.
network
low complexity
drupal debian CWE-200
5.0
2012-05-21 CVE-2012-2922 Information Exposure vulnerability in Drupal
The request_path function in includes/bootstrap.inc in Drupal 7.14 and earlier allows remote attackers to obtain sensitive information via the q[] parameter to index.php, which reveals the installation path in an error message.
network
low complexity
drupal CWE-200
5.0
2009-09-24 CVE-2009-3352 Unspecified vulnerability in Drupal
Multiple unspecified vulnerabilities in the quota_by_role (Quota by role) module for Drupal have unknown impact and attack vectors.
network
low complexity
drupal
critical
10.0