Page 5 of 22 results (0.006 seconds)

CVSS: 5.0EPSS: 0%CPEs: 7EXPL: 0

The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments, which allows remote attackers to obtain sensitive information. El módulo Talk 5.x y versiones anteriores a 5.x-1.3 y 6.x y versiones anteriores a 6.x-1.5, para Drupal, no realiza comprobación de acceso para un nodo antes de mostrar comentarios, lo que permite a los atacantes remotos obtener información delicada. • http://drupal.org/node/309758 http://secunia.com/advisories/31908 http://www.securityfocus.com/bid/31236 http://www.vupen.com/english/advisories/2008/2615 https://exchange.xforce.ibmcloud.com/vulnerabilities/45223 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.0EPSS: 0%CPEs: 7EXPL: 0

Google Talk before 1.0.0.76, with email notification enabled, allows remote attackers to cause a denial of service (connection reset) via email with a blank sender. • http://marc.info/?l=bugtraq&m=113156797404902&w=2 http://marc.info/?l=bugtraq&m=113200923423283&w=2 http://www.securityfocus.com/bid/15369 https://exchange.xforce.ibmcloud.com/vulnerabilities/23041 • CWE-20: Improper Input Validation •