Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 836

Количество 53 836

redhat логотип

CVE-2014-8172

почти 13 лет назад

The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified use of Asynchronous I/O (AIO) operations.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2014-8171

больше 11 лет назад

The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.

CVSS2: 5.7
EPSS: Низкий
redhat логотип

CVE-2014-8170

больше 11 лет назад

ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2014-8169

больше 11 лет назад

automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges via a Trojan horse program in the user home directory.

CVSS2: 4.6
EPSS: Низкий
redhat логотип

CVE-2014-8168

больше 11 лет назад

Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2014-8167

больше 12 лет назад

vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-8166

больше 11 лет назад

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-8165

почти 12 лет назад

scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2014-8164

больше 11 лет назад

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2014-8163

больше 11 лет назад

Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2014-8162

больше 11 лет назад

XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-8161

больше 11 лет назад

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.

CVSS2: 3.5
EPSS: Низкий
redhat логотип

CVE-2014-8160

почти 12 лет назад

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2014-8159

больше 11 лет назад

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

CVSS2: 6.2
EPSS: Низкий
redhat логотип

CVE-2014-8158

больше 11 лет назад

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

CVSS2: 5.1
EPSS: Средний
redhat логотип

CVE-2014-8157

больше 11 лет назад

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

CVSS2: 6.8
EPSS: Средний
redhat логотип

CVE-2014-8155

больше 16 лет назад

GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-8154

больше 11 лет назад

The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overflow.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2014-8153

больше 11 лет назад

The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2014-8152

больше 11 лет назад

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.

CVSS2: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-8172

The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified use of Asynchronous I/O (AIO) operations.

CVSS2: 4.9
0%
Низкий
почти 13 лет назад
redhat логотип
CVE-2014-8171

The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.

CVSS2: 5.7
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8170

ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.

CVSS2: 6
4%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8169

automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges via a Trojan horse program in the user home directory.

CVSS2: 4.6
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8168

Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

CVSS3: 7.8
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8167

vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-8166

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to execute arbitrary code via a crafted printer name.

CVSS2: 4.3
4%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8165

scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.

CVSS2: 6.8
3%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-8164

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.

CVSS2: 5.8
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8163

Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.

CVSS2: 4.9
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8162

XML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbitrary files and possibly have other unspecified impact via unknown vectors.

CVSS2: 4.3
3%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8161

PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and then reading the error message.

CVSS2: 3.5
3%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8160

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.

CVSS2: 5.8
5%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-8159

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict use of User Verbs for registration of memory regions, which allows local users to access arbitrary physical memory locations, and consequently cause a denial of service (system crash) or gain privileges, by leveraging permissions on a uverbs device under /dev/infiniband/.

CVSS2: 6.2
0%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8158

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

CVSS2: 5.1
14%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-8157

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

CVSS2: 6.8
17%
Средний
больше 11 лет назад
redhat логотип
CVE-2014-8155

GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
redhat логотип
CVE-2014-8154

The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which trigger a heap-based buffer overflow.

CVSS2: 6.8
3%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8153

The L3 agent in OpenStack Neutron 2014.2.x before 2014.2.2, when using radvd 2.0+, allows remote authenticated users to cause a denial of service (blocked router update processing) by creating eight routers and assigning an ipv6 non-provider subnet to each.

CVSS2: 1.7
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8152

Apache Santuario XML Security for Java 2.0.x before 2.0.3 allows remote attackers to bypass the streaming XML signature protection mechanism via a crafted XML document.

CVSS2: 5.8
6%
Низкий
больше 11 лет назад

Уязвимостей на страницу