Drupal Security Announcements

This list is for security announcements sent out be the Drupal security team.

URL

RSS feed
http://drupal.org/taxonomy/term/44/0

Last update

4 hours 27 min ago

November 5, 2008

18:51
  • Advisory ID: DRUPAL-SA-2008-069
  • Project: Content Construction Kit (third-party module)
  • Versions: 5.x, 6.x
  • Date: 2008-November-5
  • Security risk: Minor
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting
read more

October 22, 2008

20:34
  • Advisory ID: DRUPAL-SA-2008-068
  • Project: Localization client and Localization server (third-party modules)
  • Versions: 5.x, 6.x
  • Date: 2008-October-22
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Cross site request forgery
read more
19:06
  • Advisory ID: DRUPAL-SA-2008-067
  • Project: Drupal core
  • Versions: 5.x and 6.x
  • Date: 2008-October-22
  • Security risk: Less Critical
  • Exploitable from: Local/Remote
  • Vulnerability: Multiple vulnerabilities
read more

October 15, 2008

19:02
  • Advisory ID: DRUPAL-SA-2008-066
  • Project: Shindig-Integrator (third-party module)
  • Versions: 5.x
  • Date: 2008-October-15
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities
read more
18:27
  • Advisory ID: DRUPAL-SA-2008-065
  • Project: Node Clone (third-party module)
  • Version: 6.x, and 5.x.
  • Date: 2008-October-15
  • Security risk: Less critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
read more
16:46
  • Advisory ID: DRUPAL-SA-2008-064
  • Project: Node Vote (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-October-15
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL injection
read more

October 9, 2008

19:41
  • Advisory ID: DRUPAL-SA-2008-063
  • Project: Several Third-Party Modules incorrectly updated for the Drupal 6 menu system
  • Version: 6.x
  • Date: 2008-October-8
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
read more

October 8, 2008

21:47
  • Advisory ID: DRUPAL-SA-2008-062
  • Project: SIOC (third-party module)
  • Versions: 5.x and 6.x
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
read more
21:45
  • Advisory ID: DRUPAL-SA-2008-061
  • Project: EveryBlog (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-October-08
  • Security risk: Highly critical
  • Exploitable from: Remote
  • Vulnerability:SQL injection, Cross-site scripting (XSS), Privilege escalation, access bypass
read more
21:43
  • Advisory ID: DRUPAL-SA-2008-060
  • Project: Drupal core
  • Versions: 5.x and 6.x
  • Date: 2008-October-8
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Multiple vulnerabilities
read more
21:28
  • Advisory ID: DRUPAL-SA-2008-063
  • Project: Several Third-Party Modules incorrectly updated for the Drupal 6 menu system
  • Version: 6.x
  • Date: 2008-October-8
  • Security risk: Moderately critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
read more

October 1, 2008

20:24
  • Advisory ID: DRUPAL-SA-2008-059
  • Project: Brilliant Gallery (third-party module)
  • Versions: 5.x
  • Date: 2008-October-1
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL injection and Cross Site Scripting
read more

September 24, 2008

22:42
  • Advisory ID: DRUPAL-SA-2008-058
  • Project: Brilliant Gallery (third-party module)
  • Versions: 5.x, 6.x
  • Date: 2008-September-25
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL injection
read more
19:48
  • Advisory ID: DRUPAL-SA-2008-057
  • Project: Ajax Checklist (third-party module)
  • Versions: 5.x
  • Date: 2008-September-24
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: SQL injection, Cross site scripting
read more
18:58
  • Advisory ID: DRUPAL-SA-2008-056
  • Project: Simplenews (third-party module)
  • Versions: 5.x, 6.x
  • Date: 2008-September-24
  • Security risk: Not Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting
read more
18:13
  • Advisory ID: DRUPAL-SA-2008-055
  • Project: Stock (third-party module)
  • Versions: 6.x
  • Date: 2008-September-24
  • Security risk: Moderately Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting
read more
16:54
  • Advisory ID: DRUPAL-SA-2008-054
  • Project: Plugin Manager (third-party module)
  • Versions: 6.x
  • Date: 2008-September-24
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Access bypass
read more

September 18, 2008

13:31
  • Advisory ID: DRUPAL-SA-2008-053
  • Project: Answers (third-party module)
  • Versions: 5.x
  • Date: 2008-September-18
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting
read more

September 17, 2008

19:13
  • Advisory ID: DRUPAL-SA-2008-052
  • Project: Link To Us (third-party module)
  • Versions: 5.x
  • Date: 2008-September-17
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting
read more
17:20
  • Advisory ID: DRUPAL-SA-2008-051
  • Project: Mailsave (third-party module)
  • Versions: 5.x and 6.x
  • Date: 2008-September-17
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Cross site scripting
read more
Showing 1 - 20 of 24.
Next › Last »