Vulnerabilities (CVE)

Filtered by vendor Entity Api Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-1398 2 Entity Api Project, Fedoraproject 2 Entity Api, Fedora 2018-05-18 4.0 MEDIUM 6.5 MEDIUM
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.
CVE-2014-1400 2 Entity Api Project, Fedoraproject 2 Entity Api, Fedora 2018-05-18 4.0 MEDIUM 6.5 MEDIUM
The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.
CVE-2014-1399 2 Entity Api Project, Fedoraproject 2 Entity Api, Fedora 2018-05-18 4.0 MEDIUM 6.5 MEDIUM
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.