|
286131
|
4.2 |
MEDIUM
Physics
|
gnupg debian
|
gnupg libgcrypt debian_linux
|
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determi…
|
CWE-200
Information Exposure
|
CVE-2014-3591
|
2024-11-21 11:08 |
2019-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286132
|
9.8 |
CRITICAL
Network
|
redhat
|
redhat-upgrade-tool enterprise_linux
|
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2014-3585
|
2024-11-21 11:08 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286133
|
9.8 |
CRITICAL
Network
|
redhat
|
jboss_enterprise_web_server edeploy
|
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
|
CWE-74
Injection
|
CVE-2014-3700
|
2024-11-21 11:08 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286134
|
4.3 |
MEDIUM
Network
|
redhat
|
keycloak jboss_enterprise_web_server
|
JBoss KeyCloak is vulnerable to soft token deletion via CSRF
|
CWE-352
Origin Validation Error
|
CVE-2014-3655
|
2024-11-21 11:08 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286135
|
6.1 |
MEDIUM
Network
|
redhat
|
openshift_origin
|
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
|
CWE-79
Cross-site Scripting
|
CVE-2014-3592
|
2024-11-21 11:08 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286136
|
6.5 |
MEDIUM
Network
|
redhat
|
hornetq
|
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
|
CWE-611
XXE
|
CVE-2014-3599
|
2024-11-21 11:08 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286137
|
6.1 |
MEDIUM
Network
|
redhat
|
jboss_aerogear
|
JBoss AeroGear has reflected XSS via the password field
|
CWE-79
Cross-site Scripting
|
CVE-2014-3649
|
2024-11-21 11:08 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286138
|
6.5 |
MEDIUM
Adjacent
|
citrix
|
xenserver
|
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.
|
CWE-20
Improper Input Validation
|
CVE-2014-3798
|
2024-11-21 11:08 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286139
|
5.9 |
MEDIUM
Network
|
shibboleth
|
identity_provider opensaml_java
|
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain …
|
CWE-297
Improper Validation of Certificate with Host Mismatch
|
CVE-2014-3603
|
2024-11-21 11:08 |
2019-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286140
|
9.8 |
CRITICAL
Network
|
rope_project
|
rope
|
base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.
|
NVD-CWE-noinfo
|
CVE-2014-3539
|
2024-11-21 11:08 |
2018-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|