|
281291
|
- |
|
fedoraproject docker
|
fedora docker
|
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3499
|
2024-11-21 11:08 |
2014-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281292
|
- |
|
redhat
|
enterprise_virtualization
|
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via un…
|
CWE-200
Information Exposure
|
CVE-2014-3485
|
2024-11-21 11:08 |
2014-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281293
|
- |
|
php debian
|
php debian_linux
|
The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers …
|
NVD-CWE-noinfo
|
CVE-2014-3515
|
2024-11-21 11:08 |
2014-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281294
|
- |
|
php file_project debian opensuse oracle
|
php file debian_linux opensuse linux
|
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remot…
|
CWE-20
Improper Input Validation
|
CVE-2014-3487
|
2024-11-21 11:08 |
2014-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281295
|
- |
|
php file_project debian opensuse oracle
|
php file debian_linux opensuse linux
|
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows r…
|
NVD-CWE-noinfo
|
CVE-2014-3480
|
2024-11-21 11:08 |
2014-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281296
|
- |
|
php file_project debian opensuse oracle
|
php file debian_linux opensuse linux
|
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows r…
|
NVD-CWE-noinfo
|
CVE-2014-3479
|
2024-11-21 11:08 |
2014-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281297
|
- |
|
christos_zoulas php
|
file php
|
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3478
|
2024-11-21 11:08 |
2014-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281298
|
- |
|
redhat
|
cloudforms_3.0_management_engine
|
lib/util/miq-password.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 uses a hard-coded salt, which makes it easier for remote attackers to guess passwords via a brute force atta…
|
CWE-255
Credentials Management
|
CVE-2014-3489
|
2024-11-21 11:08 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281299
|
- |
|
redhat
|
cloudforms_3.0_management_engine
|
The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users …
|
CWE-59
Link Following
|
CVE-2014-3486
|
2024-11-21 11:08 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281300
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary …
|
CWE-200
Information Exposure
|
CVE-2014-3481
|
2024-11-21 11:08 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|