|
282851
|
- |
|
redhat
|
cloudforms_3.0_management_engine
|
Cross-site scripting (XSS) vulnerability in application/panel_control in CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to inject arbitrary web script or HTML via unsp…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0176
|
2024-11-21 11:01 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282852
|
- |
|
apache redhat
|
cxf jboss_enterprise_application_platform
|
The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the Userna…
|
CWE-310
Cryptographic Issues
|
CVE-2014-0035
|
2024-11-21 11:01 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282853
|
- |
|
apache redhat
|
cxf jboss_enterprise_application_platform
|
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an i…
|
CWE-20
Improper Input Validation
|
CVE-2014-0034
|
2024-11-21 11:01 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282854
|
- |
|
fedoraproject redhat libreoffice canonical opensuse
|
fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server libreoffice ubuntu_linux opensuse
|
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
|
NVD-CWE-noinfo
|
CVE-2014-0247
|
2024-11-21 11:01 |
2014-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282855
|
- |
|
microsoft
|
internet_explorer
|
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site that triggers i…
|
NVD-CWE-Other
|
CVE-2014-0325
|
2024-11-21 11:01 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282856
|
- |
|
linux
|
linux_kernel
|
Array index error in the aio_read_events_ring function in fs/aio.c in the Linux kernel through 3.15.1 allows local users to obtain sensitive information from kernel memory via a large head value.
|
NVD-CWE-Other
|
CVE-2014-0206
|
2024-11-21 11:01 |
2014-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282857
|
- |
|
samba
|
samba
|
The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) vi…
|
CWE-20
Improper Input Validation
|
CVE-2014-0244
|
2024-11-21 11:01 |
2014-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282858
|
5.5 |
MEDIUM
Local
|
linux oracle
|
linux_kernel linux
|
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause…
|
CWE-416
Use After Free
|
CVE-2014-0203
|
2024-11-21 11:01 |
2014-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282859
|
- |
|
theforeman
|
foreman
|
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.
|
NVD-CWE-Other
|
CVE-2014-0007
|
2024-11-21 11:01 |
2014-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282860
|
- |
|
redhat
|
enterprise_linux
|
A certain tomcat7 package for Apache Tomcat 7 in Red Hat Enterprise Linux (RHEL) 7 allows remote attackers to cause a denial of service (CPU consumption) via a crafted request. NOTE: this vulnerabil…
|
NVD-CWE-Other
|
CVE-2014-0186
|
2024-11-21 11:01 |
2014-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|