Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 428

Количество 53 428

redhat логотип

CVE-2014-0104

почти 12 лет назад

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0102

больше 12 лет назад

The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings are identical, which allows local users to cause a denial of service (OOPS) via crafted keyctl commands.

CVSS2: 5.2
EPSS: Низкий
redhat логотип

CVE-2014-0101

больше 12 лет назад

The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.

CVSS2: 7.1
EPSS: Низкий
redhat логотип

CVE-2014-0100

больше 12 лет назад

Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.

CVSS2: 7.6
EPSS: Низкий
redhat логотип

CVE-2014-0099

около 12 лет назад

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2014-0098

больше 12 лет назад

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2014-0097

больше 12 лет назад

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2014-0096

около 12 лет назад

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2014-0095

около 12 лет назад

java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2014-0094

больше 12 лет назад

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

CVSS2: 5
EPSS: Критический
redhat логотип

CVE-2014-0093

больше 12 лет назад

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2014-0092

больше 12 лет назад

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS2: 5.8
EPSS: Средний
redhat логотип

CVE-2014-0091

больше 12 лет назад

Foreman has improper input validation which could lead to partial Denial of Service

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2014-0090

больше 12 лет назад

Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.

CVSS2: 3.6
EPSS: Низкий
redhat логотип

CVE-2014-0089

больше 12 лет назад

Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2014-0088

больше 12 лет назад

The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2014-0087

больше 11 лет назад

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC checking, related to the rbac_user_edit action.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2014-0086

больше 12 лет назад

The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0084

больше 12 лет назад

Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2014-0083

больше 12 лет назад

The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.

CVSS2: 1.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-0104

In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

CVSS2: 4.3
1%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-0102

The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings are identical, which allows local users to cause a denial of service (OOPS) via crafted keyctl commands.

CVSS2: 5.2
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0101

The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an SCTP handshake with a modified INIT chunk and a crafted AUTH chunk before a COOKIE_ECHO chunk.

CVSS2: 7.1
7%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0100

Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.

CVSS2: 7.6
3%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0099

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.

CVSS2: 5.8
9%
Низкий
около 12 лет назад
redhat логотип
CVE-2014-0098

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.

CVSS2: 4.3
26%
Средний
больше 12 лет назад
redhat логотип
CVE-2014-0097

The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.

CVSS2: 7.5
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0096

java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which allows remote attackers to bypass security-manager restrictions and read arbitrary files via a crafted web application that provides an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 2.1
7%
Низкий
около 12 лет назад
redhat логотип
CVE-2014-0095

java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.

CVSS2: 5
8%
Низкий
около 12 лет назад
redhat логотип
CVE-2014-0094

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

CVSS2: 5
100%
Критический
больше 12 лет назад
redhat логотип
CVE-2014-0093

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.

CVSS2: 4
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0092

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS2: 5.8
30%
Средний
больше 12 лет назад
redhat логотип
CVE-2014-0091

Foreman has improper input validation which could lead to partial Denial of Service

CVSS2: 4
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0090

Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.

CVSS2: 3.6
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0089

Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.

CVSS2: 6
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0088

The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.

CVSS2: 5.1
9%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0087

The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC checking, related to the rbac_user_edit action.

CVSS2: 6.5
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-0086

The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests.

CVSS2: 4.3
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0084

Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly.

CVSS2: 2.1
0%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0083

The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.

CVSS2: 1.9
0%
Низкий
больше 12 лет назад

Уязвимостей на страницу