|
280141
|
7.5 |
HIGH
Network
|
docker opensuse
|
cs_engine docker opensuse
|
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 does not properly validate and extract the manifest object from its JSON representation during a pull, which allows attackers to injec…
|
CWE-20
Improper Input Validation
|
CVE-2014-8179
|
2024-11-21 11:18 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280142
|
5.5 |
MEDIUM
Local
|
docker opensuse
|
cs_engine docker opensuse
|
Docker Engine before 1.8.3 and CS Docker Engine before 1.6.2-CS7 do not use a globally unique identifier to store image layers, which makes it easier for attackers to poison the image cache via a cra…
|
CWE-20
Improper Input Validation
|
CVE-2014-8178
|
2024-11-21 11:18 |
2019-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280143
|
8.8 |
HIGH
Network
|
dasanzhone
|
znid_2426a_firmware
|
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direc…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2014-8356
|
2024-11-21 11:18 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280144
|
5.9 |
MEDIUM
Network
|
redhat
|
enterprise_virtualization vdsclient virtual_desktop_server_manager
|
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
|
CWE-295
Improper Certificate Validation
|
CVE-2014-8167
|
2024-11-21 11:18 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280145
|
5.5 |
MEDIUM
Local
|
redhat
|
enterprise_linux enterprise_mrg
|
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
|
CWE-665
Improper Initialization
|
CVE-2014-8181
|
2024-11-21 11:18 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280146
|
7.8 |
HIGH
Local
|
liblouis
|
liblouis
|
A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause appl…
|
-
|
CVE-2014-8184
|
2024-11-21 11:18 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280147
|
7.4 |
HIGH
Network
|
theforeman redhat
|
foreman satellite
|
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource…
|
-
|
CVE-2014-8183
|
2024-11-21 11:18 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280148
|
6.5 |
MEDIUM
Network
|
libtiff redhat apple
|
libtiff enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_linux_server_eus mac_os_x…
|
The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a craf…
|
CWE-369
Divide By Zero
|
CVE-2014-8130
|
2024-11-21 11:18 |
2018-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280149
|
8.8 |
HIGH
Network
|
libtiff debian redhat apple
|
libtiff debian_linux enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_server enterprise_linux_server_eus mac_os_x iphone_os
|
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c t…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-8129
|
2024-11-21 11:18 |
2018-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280150
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux enterprise_mrg
|
The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes within a memory-constrained cgroup.
|
CWE-399
Resource Management Errors
|
CVE-2014-8171
|
2024-11-21 11:18 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|