|
279571
|
- |
|
openssl
|
openssl
|
Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted handshake message.
|
CWE-20
Improper Input Validation
|
CVE-2014-3513
|
2024-11-21 11:08 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279572
|
- |
|
cisco
|
prime_optical
|
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Prime Optical 10 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuq80…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3408
|
2024-11-21 11:08 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279573
|
- |
|
cisco
|
intrusion_prevention_system
|
Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP t…
|
CWE-362
Race Condition
|
CVE-2014-3406
|
2024-11-21 11:08 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279574
|
- |
|
cisco
|
telepresence_mcu_software
|
The network stack in Cisco TelePresence MCU Software before 4.3(2.30) allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets, aka Bug ID CSCtz35468.
|
CWE-399
Resource Management Errors
|
CVE-2014-3397
|
2024-11-21 11:08 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279575
|
- |
|
redhat
|
enterprise_virtualization_manager
|
The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to read arbitrary files or…
|
CWE-20
Improper Input Validation
|
CVE-2014-3573
|
2024-11-21 11:08 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279576
|
- |
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
|
CWE-200
Information Exposure
|
CVE-2014-3680
|
2024-11-21 11:08 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279577
|
- |
|
jenkins-ci
|
monitoring_plugin
|
The Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to obtain sensitive information by accessing unspecified pages.
|
NVD-CWE-noinfo
|
CVE-2014-3679
|
2024-11-21 11:08 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279578
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information …
|
CWE-200
Information Exposure
|
CVE-2014-3667
|
2024-11-21 11:08 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279579
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.
|
CWE-94
Code Injection
|
CVE-2014-3666
|
2024-11-21 11:08 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279580
|
- |
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified ve…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3663
|
2024-11-21 11:08 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|