|
280411
|
- |
|
redhat jenkins
|
openshift jenkins
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3681
|
2024-11-21 11:08 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280412
|
- |
|
jenkins redhat
|
jenkins openshift
|
Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Overall/READ permission to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2014-3664
|
2024-11-21 11:08 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280413
|
- |
|
scientificlinux
|
luci
|
Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted cluster configuration.
|
CWE-94
Code Injection
|
CVE-2014-3593
|
2024-11-21 11:08 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280414
|
3.4 |
LOW
Network
|
redhat ibm apple mageia novell opensuse fedoraproject openssl netbsd debian oracle
|
enterprise_linux_desktop_supplementary enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_supplementary enterprise_linux_workstation_…
|
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a pad…
|
CWE-310
Cryptographic Issues
|
CVE-2014-3566
|
2024-11-21 11:08 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280415
|
- |
|
juniper
|
junos srx100 srx110 srx1400 srx210 srx220 srx240 srx3400 srx3600 srx550 srx5600 srx5800 srx650
|
The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25, and 12.1X47 before 12.1X47-D10, when an Applicati…
|
CWE-20
Improper Input Validation
|
CVE-2014-3825
|
2024-11-21 11:08 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280416
|
- |
|
juniper
|
junos
|
Juniper Junos OS 9.1 through 11.4 before 11.4R11, 12.1 before R10, 12.1X44 before D40, 12.1X46 before D30, 12.1X47 before D11 and 12.147-D15, 12.1X48 before D41 and D62, 12.2 before R8, 12.2X50 befor…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3818
|
2024-11-21 11:08 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280417
|
- |
|
jenkins-ci
|
monitoring_plugin
|
Cross-site scripting (XSS) vulnerability in the Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3678
|
2024-11-21 11:08 |
2014-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280418
|
- |
|
apache canonical redhat oracle
|
http_server ubuntu_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_eus enterprise_manager_ops_cent…
|
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer d…
|
CWE-476
NULL Pointer Dereference
|
CVE-2014-3581
|
2024-11-21 11:08 |
2014-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280419
|
- |
|
cisco
|
intrusion_prevention_system
|
The authentication-manager process in the web framework in Cisco Intrusion Prevention System (IPS) 7.0(8)E4 and earlier in Cisco Intrusion Detection System (IDS) does not properly manage user tokens,…
|
CWE-287
Improper Authentication
|
CVE-2014-3402
|
2024-11-21 11:08 |
2014-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280420
|
- |
|
cisco
|
adaptive_security_virtual_appliance adaptive_security_appliance_software
|
The Smart Call Home (SCH) implementation in Cisco ASA Software 8.2 before 8.2(5.50), 8.4 before 8.4(7.15), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.8), and 9.1 before 9.1(5.1) all…
|
CWE-295
Improper Certificate Validation
|
CVE-2014-3394
|
2024-11-21 11:08 |
2014-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|