Latest CVE Feed
-
5.5
MEDIUMCVE-2014-0241
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable... Read more
- EPSS Score: %0.10
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-0234
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Open... Read more
Affected Products : openshift- EPSS Score: %1.42
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-0212
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors... Read more
Affected Products : qpid-cpp- EPSS Score: %3.47
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-0197
CFME: CSRF protection vulnerability via permissive check of the referrer header... Read more
- EPSS Score: %0.36
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-0183
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.... Read more
Affected Products : subscription_asset_manager- EPSS Score: %0.29
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.60
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-0169
In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without p... Read more
Affected Products : jboss_enterprise_application_platform- EPSS Score: %0.18
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2014-0163
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.... Read more
Affected Products : openshift- EPSS Score: %1.79
- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-0161
ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attac... Read more
Affected Products : ovirt-engine-sdk-python- EPSS Score: %0.10
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-0158
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file because of incorrect j2k_decode, j... Read more
- EPSS Score: %0.51
- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-0156
Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command.... Read more
Affected Products : awesomespawn- EPSS Score: %2.74
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-0148
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fie... Read more
- EPSS Score: %0.06
- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
6.2
MEDIUMCVE-2014-0147
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly ca... Read more
- EPSS Score: %0.05
- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2014-0144
QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arb... Read more
- EPSS Score: %1.98
- Published: Sep. 29, 2022
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-0104
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.... Read more
Affected Products : fence-agents- EPSS Score: %0.30
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-0091
Foreman has improper input validation which could lead to partial Denial of Service... Read more
Affected Products : foreman- EPSS Score: %0.51
- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-0087
The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging improper RBAC ch... Read more
Affected Products : cloudforms_management_engine- EPSS Score: %0.10
- Published: Jan. 11, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-0084
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly.... Read more
Affected Products : openshift_origin- EPSS Score: %0.13
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-0083
The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.... Read more
- EPSS Score: %0.07
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-0068
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.... Read more
- EPSS Score: %0.04
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024