|
286121
|
6.1 |
MEDIUM
Network
|
redhat
|
subscription_asset_manager
|
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
|
CWE-79
Cross-site Scripting
|
CVE-2014-0183
|
2024-11-21 11:01 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286122
|
6.5 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform
|
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to acc…
|
CWE-863
Incorrect Authorization
|
CVE-2014-0169
|
2024-11-21 11:01 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286123
|
9.8 |
CRITICAL
Network
|
tigervnc
|
tigervnc
|
Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vn…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-0011
|
2024-11-21 11:01 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286124
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7486
|
2024-11-21 11:01 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286125
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7485
|
2024-11-21 11:01 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286126
|
5.9 |
MEDIUM
Network
|
ovirt-engine-sdk-python_project
|
ovirt-engine-sdk-python
|
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a T…
|
CWE-295
Improper Certificate Validation
|
CVE-2014-0161
|
2024-11-21 11:01 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286127
|
5.9 |
MEDIUM
Network
|
clusterlabs
|
fence-agents
|
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary S…
|
CWE-295
Improper Certificate Validation
|
CVE-2014-0104
|
2024-11-21 11:01 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286128
|
9.8 |
CRITICAL
Network
|
docker apache
|
docker geode
|
An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.
|
CWE-20
Improper Input Validation
|
CVE-2014-0048
|
2024-11-21 11:01 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286129
|
5.5 |
MEDIUM
Local
|
theforeman redhat
|
hammer_cli satellite
|
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2014-0241
|
2024-11-21 11:01 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286130
|
7.5 |
HIGH
Network
|
apache
|
qpid-cpp
|
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2014-0212
|
2024-11-21 11:01 |
2019-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|