|
283701
|
- |
|
redhat
|
enterprise_mrg
|
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers…
|
CWE-200
Information Exposure
|
CVE-2014-0174
|
2024-11-21 11:01 |
2014-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283702
|
- |
|
christos_zoulas php oracle opensuse debian
|
file php linux opensuse debian_linux
|
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0207
|
2024-11-21 11:01 |
2014-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283703
|
- |
|
redhat
|
jboss_enterprise_web_platform jboss_enterprise_application_platform jboss_web_framework_kit
|
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote at…
|
CWE-94
Code Injection
|
CVE-2014-0248
|
2024-11-21 11:01 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283704
|
- |
|
redhat
|
cloudforms_3.0_management_engine
|
Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 logs the root password when deploying a VM, which allows local users to obtain sensitive information by reading the evm.log file.
|
CWE-255
Credentials Management
|
CVE-2014-0184
|
2024-11-21 11:01 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283705
|
- |
|
redhat
|
cloudforms_3.0_management_engine
|
The wait_for_task function in app/controllers/application_controller.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to cause a denial of service (infinit…
|
CWE-399
Resource Management Errors
|
CVE-2014-0180
|
2024-11-21 11:01 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283706
|
- |
|
redhat
|
cloudforms_3.0_management_engine
|
Cross-site scripting (XSS) vulnerability in application/panel_control in CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to inject arbitrary web script or HTML via unsp…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0176
|
2024-11-21 11:01 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283707
|
- |
|
apache redhat
|
cxf jboss_enterprise_application_platform
|
The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the Userna…
|
CWE-310
Cryptographic Issues
|
CVE-2014-0035
|
2024-11-21 11:01 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283708
|
- |
|
apache redhat
|
cxf jboss_enterprise_application_platform
|
The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an i…
|
CWE-20
Improper Input Validation
|
CVE-2014-0034
|
2024-11-21 11:01 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283709
|
- |
|
fedoraproject redhat libreoffice canonical opensuse
|
fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server libreoffice ubuntu_linux opensuse
|
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
|
NVD-CWE-noinfo
|
CVE-2014-0247
|
2024-11-21 11:01 |
2014-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283710
|
- |
|
microsoft
|
internet_explorer
|
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site that triggers i…
|
NVD-CWE-Other
|
CVE-2014-0325
|
2024-11-21 11:01 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|