|
287021
|
- |
|
apache
|
tomcat
|
Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers t…
|
CWE-189
Numeric Errors
|
CVE-2014-0099
|
2024-11-21 11:01 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287022
|
- |
|
apache
|
tomcat
|
java/org/apache/catalina/servlets/DefaultServlet.java in the default servlet in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 does not properly restrict XSLT stylesheets, which…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0096
|
2024-11-21 11:01 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287023
|
- |
|
apache
|
tomcat
|
java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP req…
|
CWE-20
Improper Input Validation
|
CVE-2014-0095
|
2024-11-21 11:01 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287024
|
- |
|
apache
|
tomcat
|
Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4 allows remot…
|
CWE-189
Numeric Errors
|
CVE-2014-0075
|
2024-11-21 11:01 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287025
|
- |
|
redhat
|
rhevm-dwh
|
The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh) package before 3.3.3, stores the history database password in cleartext, whic…
|
CWE-255
Credentials Management
|
CVE-2014-0202
|
2024-11-21 11:01 |
2014-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287026
|
- |
|
sosreport_project
|
sosreport
|
SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitive information by reading the archive.
|
CWE-255
Credentials Management
|
CVE-2014-0246
|
2024-11-21 11:01 |
2014-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287027
|
- |
|
redhat
|
rhevm-reports
|
ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports package (rhevm-reports) before 3.3.3, uses world-readable permissions on configuration files, which allows local users t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0201
|
2024-11-21 11:01 |
2014-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287028
|
- |
|
redhat
|
rhevm-reports
|
The Red Hat Enterprise Virtualization Manager reports (rhevm-reports) package before 3.3.3-1 uses world-readable permissions on the datasource configuration file (js-jboss7-ds.xml), which allows loca…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0200
|
2024-11-21 11:01 |
2014-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287029
|
- |
|
redhat
|
rhevm-reports
|
The setup script in ovirt-engine-reports, as used in the Red Hat Enterprise Virtualization reports (rhevm-reports) package before 3.3.3, stores the reports database password in cleartext, which allow…
|
CWE-310
Cryptographic Issues
|
CVE-2014-0199
|
2024-11-21 11:01 |
2014-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287030
|
- |
|
samba
|
samba
|
The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a den…
|
CWE-20
Improper Input Validation
|
CVE-2014-0239
|
2024-11-21 11:01 |
2014-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|