Vulnerabilities > Drupal > Drupal > 7.3

DATE CVE VULNERABILITY TITLE RISK
2014-07-22 CVE-2014-5020 Permissions, Privileges, and Access Controls vulnerability in Drupal
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.
network
drupal CWE-264
4.9
2014-07-22 CVE-2014-5019 Improper Input Validation vulnerability in Drupal
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.
network
low complexity
drupal CWE-20
5.0
2014-04-23 CVE-2014-2983 Information Exposure vulnerability in multiple products
Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.
network
low complexity
drupal debian CWE-200
5.0
2014-01-19 CVE-2013-0244 Cross-Site Scripting vulnerability in Drupal
Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements.
network
high complexity
drupal CWE-79
2.6
2013-12-24 CVE-2013-6388 Cross-Site Scripting vulnerability in Drupal
Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.
network
drupal CWE-79
4.3
2013-12-24 CVE-2013-6387 Cross-Site Scripting vulnerability in Drupal
Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.
network
high complexity
drupal CWE-79
2.1
2013-12-07 CVE-2013-6389 Improper Input Validation vulnerability in Drupal
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
network
drupal CWE-20
5.8
2013-12-07 CVE-2013-6386 Cryptographic Issues vulnerability in Drupal
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack.
network
drupal CWE-310
6.8
2013-12-07 CVE-2013-6385 Code Injection vulnerability in Drupal
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors.
network
high complexity
drupal CWE-94
5.1
2013-10-28 CVE-2012-0827 Permissions, Privileges, and Access Controls vulnerability in Drupal
The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors.
network
drupal CWE-264
3.5