Policy on release versions and permissions - PSA-2010-001

Date: 
2010-May-13
  • Advisory ID: PSA-2010-001
  • Project: Drupal core and contrib
  • Versions: 5.x and 6.x and above
  • Date: 2010-May-13
  • Security risk: None

SA-CONTRIB-2010-048: CiviRegister - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-048
  • Project: CiviRegister (third-party module)
  • Version: 5.x, 6.x
  • Date: 2010-May-12
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2010-047: Services - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-047
  • Project: Services (third-party module)
  • Version: 6.x
  • Date: 2010-May-12
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Access Bypass

SA-CONTRIB-2010-046: Award - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-046
  • Project: Award (third-party module)
  • Version: 5.x, 6.x
  • Date: 2010-May-12
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2010-045 - Auto Assign Role - Access bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-045
  • Project: Auto Assign Role (third-party module)
  • Version: 6.x
  • Date: 2010-May-12
  • Security risk: Less Critical
  • Exploitable from: Remote
  • Vulnerability: Access Bypass

SA-CONTRIB-2010-044: Bibliography - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-044
  • Project: Bibliography (third-party module)
  • Version: 5.x, 6.x
  • Date: 2010-May-12
  • Security risk: Moderately Critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2010-043: Wordfilter - Cross Site Scripting

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-043
  • Project: Wordfilter (third-party module)
  • Version: 5.x, 6.x
  • Date: 2010-May-12
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross Site Scripting

SA-CONTRIB-2010-042: LoginToboggan - Session fixation

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-042
  • Project: LoginToboggan (third-party module)
  • Version: 5.x, 6.x
  • Date: 2010-05-12
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Session fixation

SA-CONTRIB-2010-041: ImageField - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-041
  • Project: ImageField (third-party module)
  • Version: 6.x
  • Date: 2010-May-5
  • Security risk: Less Critical
  • Exploitable from: Remote
  • Vulnerability: Access Bypass

SA-CONTRIB-2010-040: FileField - Access Bypass

  • Advisory ID: DRUPAL-SA-CONTRIB-2010-040
  • Project: FileField (third-party module)
  • Version: 6.x
  • Date: 2010-May-5
  • Security risk: Moderately Critical
  • Exploitable from: Remote
  • Vulnerability: Access Bypass

Pages

Subscribe with RSS Subscribe to Security advisories