Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 640

Количество 77 640

ubuntu логотип

CVE-2014-7275

почти 12 лет назад

The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof POP3 servers and obtain sensitive information via a crafted certificate.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2014-7274

почти 12 лет назад

The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate from a recognized Certification Authority.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2014-7273

почти 12 лет назад

The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-7271

больше 8 лет назад

Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2014-7231

почти 12 лет назад

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2014-7230

почти 12 лет назад

The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2014-7217

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.4, 4.1.x before 4.1.14.5, and 4.2.x before 4.2.9.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted ENUM value that is improperly handled during rendering of the (1) table search or (2) table structure page, related to libraries/TableSearch.class.php and libraries/Util.class.php.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-7210

около 1 года назад

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2014-7209

больше 11 лет назад

run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-7208

больше 11 лет назад

GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2014-7207

почти 12 лет назад

A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate arguments in ipv6_select_ident function calls, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging (1) tun or (2) macvtap device access.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2014-7206

почти 12 лет назад

The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.

CVSS2: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2014-7204

почти 12 лет назад

jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-7203

почти 12 лет назад

libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-7202

почти 12 лет назад

stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a crafted connection request.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-7199

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19, 1.22.x before 1.22.11, and 1.23.x before 1.23.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-7192

больше 11 лет назад

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2014-7191

почти 12 лет назад

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-7189

почти 12 лет назад

crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-7188

почти 12 лет назад

The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.

CVSS2: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-7275

The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof POP3 servers and obtain sensitive information via a crafted certificate.

CVSS2: 5.8
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7274

The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate from a recognized Certification Authority.

CVSS2: 5.8
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7273

The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate.

CVSS2: 6.8
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7271

Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.

CVSS3: 7.8
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2014-7231

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

CVSS2: 2.1
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7230

The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.

CVSS2: 2.1
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7217

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.4, 4.1.x before 4.1.14.5, and 4.2.x before 4.2.9.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted ENUM value that is improperly handled during rendering of the (1) table search or (2) table structure page, related to libraries/TableSearch.class.php and libraries/Util.class.php.

CVSS2: 3.5
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7210

pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends are not affected.

CVSS3: 9.8
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2014-7209

run-mailcap in the Debian mime-support package before 3.52-1+deb7u1 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.

CVSS2: 7.5
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-7208

GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label.

CVSS2: 7.2
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-7207

A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate arguments in ipv6_select_ident function calls, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging (1) tun or (2) macvtap device access.

CVSS2: 4.9
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7206

The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.

CVSS2: 3.6
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7204

jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.

CVSS2: 5
4%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7203

libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors.

CVSS2: 4.3
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7202

stream_engine.cpp in libzmq (aka ZeroMQ/C++)) 4.0.5 before 4.0.5 allows man-in-the-middle attackers to conduct downgrade attacks via a crafted connection request.

CVSS2: 4.3
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7199

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.19, 1.22.x before 1.22.11, and 1.23.x before 1.23.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG file.

CVSS2: 4.3
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7192

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.

CVSS2: 10
13%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2014-7191

The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.

CVSS2: 5
8%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7189

crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.

CVSS2: 4.3
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-7188

The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.

CVSS2: 8.3
1%
Низкий
почти 12 лет назад

Уязвимостей на страницу