|
279581
|
- |
|
jenkins redhat
|
jenkins openshift
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
|
CWE-200
Information Exposure
|
CVE-2014-3662
|
2024-11-21 11:08 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279582
|
- |
|
redhat jenkins
|
openshift jenkins
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.
|
CWE-399
Resource Management Errors
|
CVE-2014-3661
|
2024-11-21 11:08 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279583
|
- |
|
drupal debian
|
drupal debian_linux
|
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection att…
|
CWE-89
SQL Injection
|
CVE-2014-3704
|
2024-11-21 11:08 |
2014-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279584
|
- |
|
w1.fi debian canonical
|
hostapd wpa_supplicant debian_linux ubuntu_linux
|
wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via …
|
CWE-20
Improper Input Validation
|
CVE-2014-3686
|
2024-11-21 11:08 |
2014-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279585
|
- |
|
redhat jenkins
|
openshift jenkins
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3681
|
2024-11-21 11:08 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279586
|
- |
|
jenkins redhat
|
jenkins openshift
|
Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Overall/READ permission to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2014-3664
|
2024-11-21 11:08 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279587
|
- |
|
scientificlinux
|
luci
|
Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted cluster configuration.
|
CWE-94
Code Injection
|
CVE-2014-3593
|
2024-11-21 11:08 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279588
|
3.4 |
LOW
Network
|
redhat ibm apple mageia novell opensuse fedoraproject openssl netbsd debian oracle
|
enterprise_linux_desktop_supplementary enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_supplementary enterprise_linux_workstation_…
|
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a pad…
|
CWE-310
Cryptographic Issues
|
CVE-2014-3566
|
2024-11-21 11:08 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279589
|
- |
|
juniper
|
junos srx100 srx110 srx1400 srx210 srx220 srx240 srx3400 srx3600 srx550 srx5600 srx5800 srx650
|
The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25, and 12.1X47 before 12.1X47-D10, when an Applicati…
|
CWE-20
Improper Input Validation
|
CVE-2014-3825
|
2024-11-21 11:08 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279590
|
- |
|
juniper
|
junos
|
Juniper Junos OS 9.1 through 11.4 before 11.4R11, 12.1 before R10, 12.1X44 before D40, 12.1X46 before D30, 12.1X47 before D11 and 12.147-D15, 12.1X48 before D41 and D62, 12.2 before R8, 12.2X50 befor…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3818
|
2024-11-21 11:08 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|