Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 640

Количество 77 640

ubuntu логотип

CVE-2014-5037

почти 12 лет назад

Eucalyptus 4.0.0 through 4.0.1, when the log level is set to INFO, logs user and system passwords, which allows local users to obtain sensitive information by reading cloud-requests.log.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2014-5036

около 12 лет назад

The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2014-5033

около 12 лет назад

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2014-5032

больше 11 лет назад

GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensitive information via the cost criteria in the search bar.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-5031

около 12 лет назад

The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-5030

около 12 лет назад

CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2014-5029

около 12 лет назад

The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537.

CVSS2: 1.5
EPSS: Низкий
ubuntu логотип

CVE-2014-5026

почти 12 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5) Host Templates Name in a delete action; (6) Data Source Title; (7) Graph Title; or (8) Graph Template Name in a delete or (9) duplicate action.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-5025

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2014-5022

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-5021

около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2014-5020

около 12 лет назад

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2014-5019

около 12 лет назад

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-5015

около 12 лет назад

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-5013

больше 6 лет назад

DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2014-5012

больше 6 лет назад

DOMPDF before 0.6.2 allows denial of service.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2014-5011

больше 6 лет назад

DOMPDF before 0.6.2 allows Information Disclosure.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2014-5009

больше 9 лет назад

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2014-5008

больше 9 лет назад

Snoopy allows remote attackers to execute arbitrary commands.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2014-4987

около 12 лет назад

server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.

CVSS2: 4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-5037

Eucalyptus 4.0.0 through 4.0.1, when the log level is set to INFO, logs user and system passwords, which allows local users to obtain sensitive information by reading cloud-requests.log.

CVSS2: 2.1
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-5036

The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.

CVSS2: 1.9
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5033

KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

CVSS2: 6.9
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5032

GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensitive information via the cost criteria in the search bar.

CVSS2: 5
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-5031

The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.

CVSS2: 5
3%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5030

CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.

CVSS2: 1.9
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5029

The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537.

CVSS2: 1.5
0%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5026

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5) Host Templates Name in a delete action; (6) Data Source Title; (7) Graph Title; or (8) Graph Template Name in a delete or (9) duplicate action.

CVSS2: 3.5
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-5025

Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.

CVSS2: 3.5
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-5022

Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

CVSS2: 4.3
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5021

Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

CVSS2: 2.1
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5020

The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

CVSS2: 4.9
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5019

The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

CVSS2: 5
3%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5015

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

CVSS2: 5
2%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2014-5013

DOMPDF before 0.6.2 allows remote code execution, a related issue to CVE-2014-2383.

CVSS3: 8.8
4%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-5012

DOMPDF before 0.6.2 allows denial of service.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-5011

DOMPDF before 0.6.2 allows Information Disclosure.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2014-5009

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.

CVSS3: 9.8
5%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2014-5008

Snoopy allows remote attackers to execute arbitrary commands.

CVSS3: 9.8
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2014-4987

server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.

CVSS2: 4
1%
Низкий
около 12 лет назад

Уязвимостей на страницу