Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 428

Количество 53 428

redhat логотип

CVE-2014-0027

больше 12 лет назад

The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a symlink attack on /tmp/awb.wav. NOTE: some of these details are obtained from third party information.

CVSS2: 3.6
EPSS: Низкий
redhat логотип

CVE-2014-0026

около 12 лет назад

katello-headpin is vulnerable to CSRF in REST API

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0023

почти 12 лет назад

OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2014-0022

больше 12 лет назад

The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, which allows remote attackers to bypass the RMP package signing restriction via an unsigned package.

CVSS2: 7.6
EPSS: Низкий
redhat логотип

CVE-2014-0021

больше 12 лет назад

Chrony before 1.29.1 has traffic amplification in cmdmon protocol

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2014-0020

больше 12 лет назад

The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0019

больше 12 лет назад

Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2014-0018

больше 12 лет назад

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.

CVSS2: 1.9
EPSS: Низкий
redhat логотип

CVE-2014-0017

больше 12 лет назад

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0016

больше 12 лет назад

stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0015

больше 12 лет назад

cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0012

больше 12 лет назад

FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.

CVSS2: 4.4
EPSS: Низкий
redhat логотип

CVE-2014-0011

больше 12 лет назад

Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2014-0007

около 12 лет назад

The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2014-0006

больше 12 лет назад

The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-0005

больше 12 лет назад

PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.

CVSS2: 3.6
EPSS: Низкий
redhat логотип

CVE-2014-0004

больше 12 лет назад

Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.

CVSS2: 6.2
EPSS: Низкий
redhat логотип

CVE-2014-0003

больше 12 лет назад

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

CVSS2: 6
EPSS: Низкий
redhat логотип

CVE-2014-0002

больше 12 лет назад

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2014-0001

больше 12 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2014-0027

The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a symlink attack on /tmp/awb.wav. NOTE: some of these details are obtained from third party information.

CVSS2: 3.6
0%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0026

katello-headpin is vulnerable to CSRF in REST API

CVSS2: 4.3
0%
Низкий
около 12 лет назад
redhat логотип
CVE-2014-0023

OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

CVSS2: 2.1
0%
Низкий
почти 12 лет назад
redhat логотип
CVE-2014-0022

The installUpdates function in yum-cron/yum-cron.py in yum 3.4.3 and earlier does not properly check the return value of the sigCheckPkg function, which allows remote attackers to bypass the RMP package signing restriction via an unsigned package.

CVSS2: 7.6
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0021

Chrony before 1.29.1 has traffic amplification in cmdmon protocol

CVSS2: 2.6
4%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0020

The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.

CVSS2: 4.3
3%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0019

Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.

CVSS2: 2.6
0%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0018

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.

CVSS2: 1.9
0%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0017

The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared between children processes and allows local users to obtain sensitive information by leveraging a pid collision.

CVSS2: 4.3
0%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0016

stunnel before 5.00, when using fork threading, does not properly update the state of the OpenSSL pseudo-random number generator (PRNG), which causes subsequent children with the same process ID to use the same entropy pool and allows remote attackers to obtain private keys for EC (ECDSA) or DSA certificates.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0015

cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.

CVSS2: 4.3
6%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0012

FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1402.

CVSS2: 4.4
0%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0011

Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.

CVSS2: 5.1
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0007

The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.

CVSS2: 10
9%
Низкий
около 12 лет назад
redhat логотип
CVE-2014-0006

The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0005

PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.

CVSS2: 3.6
1%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0004

Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.

CVSS2: 6.2
0%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0003

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbitrary Java methods via a crafted message.

CVSS2: 6
7%
Низкий
больше 12 лет назад
redhat логотип
CVE-2014-0002

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

CVSS2: 5
33%
Средний
больше 12 лет назад
redhat логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 4
6%
Низкий
больше 12 лет назад

Уязвимостей на страницу