|
280301
|
9.8 |
CRITICAL
Network
|
apache
|
ambari
|
In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.
|
CWE-94
Code Injection
|
CVE-2014-3582
|
2024-11-21 11:08 |
2017-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280302
|
6.5 |
MEDIUM
Local
|
redhat xen
|
libvirt xen
|
The qemu implementation in libvirt before 1.3.0 and Xen allows local guest OS users to cause a denial of service (host disk consumption) by writing to stdout or stderr.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2014-3672
|
2024-11-21 11:08 |
2016-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280303
|
- |
|
jenkins
|
jenkins
|
Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveragi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3665
|
2024-11-21 11:08 |
2015-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280304
|
- |
|
apache
|
activemq
|
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with…
|
CWE-287
Improper Authentication
|
CVE-2014-3612
|
2024-11-21 11:08 |
2015-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280305
|
7.5 |
HIGH
Network
|
apache oracle
|
activemq business_intelligence_publisher fusion_middleware
|
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3576
|
2024-11-21 11:08 |
2015-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280306
|
- |
|
theforeman
|
foreman
|
Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3653
|
2024-11-21 11:08 |
2015-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280307
|
- |
|
opensuse python
|
opensuse pillow
|
The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.
|
CWE-399
Resource Management Errors
|
CVE-2014-3598
|
2024-11-21 11:08 |
2015-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280308
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
The default configuration for the Command Line Interface in Red Hat Enterprise Application Platform before 6.4.0 and WildFly (formerly JBoss Application Server) uses weak permissions for .jboss-cli-h…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3586
|
2024-11-21 11:08 |
2015-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280309
|
- |
|
opensuse gluster
|
opensuse glusterfs
|
The __socket_proto_state_machine function in GlusterFS 3.5 allows remote attackers to cause a denial of service (infinite loop) via a "00000000" fragment header.
|
CWE-399
Resource Management Errors
|
CVE-2014-3619
|
2024-11-21 11:08 |
2015-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280310
|
- |
|
redhat theforeman
|
openstack foreman
|
Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and …
|
CWE-310
Cryptographic Issues
|
CVE-2014-3691
|
2024-11-21 11:08 |
2015-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|