Latest CVE Feed
-
6.1
MEDIUMCVE-2014-3652
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.... Read more
- EPSS Score: %0.22
- Published: Dec. 15, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-3650
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.... Read more
Affected Products : jboss_aerogear- EPSS Score: %0.16
- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3649
JBoss AeroGear has reflected XSS via the password field... Read more
Affected Products : jboss_aerogear- EPSS Score: %0.34
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-3648
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless except... Read more
Affected Products : jboss_aerogear- EPSS Score: %0.32
- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-3643
jersey: XXE via parameter entities not disabled by the jersey SAX parser... Read more
Affected Products : jersey- EPSS Score: %0.42
- Published: Dec. 15, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-3626
The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other components will decode any URI passed to them. To protect against directory traversal the Grails Resource Plugin did the following: normalized ... Read more
Affected Products : resources- EPSS Score: %1.03
- Published: Mar. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3622
Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.... Read more
Affected Products : php- EPSS Score: %2.34
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-3607
DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers ... Read more
- EPSS Score: %0.21
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-3603
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName... Read more
- EPSS Score: %0.11
- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-3599
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy... Read more
Affected Products : hornetq- EPSS Score: %0.38
- Published: Nov. 12, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3592
OpenShift Origin: Improperly validated team names could allow stored XSS attacks... Read more
Affected Products : openshift_origin- EPSS Score: %0.34
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
4.2
MEDIUMCVE-2014-3591
Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuatio... Read more
- EPSS Score: %0.14
- Published: Nov. 29, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-3590
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content.... Read more
Affected Products : satellite- EPSS Score: %0.12
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-3585
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions... Read more
- EPSS Score: %0.20
- Published: Nov. 22, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3539
base/oi/doa.py in the Rope library in CPython (aka Python) allows remote attackers to execute arbitrary code by leveraging an unsafe call to pickle.load.... Read more
- EPSS Score: %2.09
- Published: Apr. 06, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-3536
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration... Read more
Affected Products : cloudforms_management_engine- EPSS Score: %0.10
- Published: Dec. 15, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-3519
The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, when using simfs, might allow local container users with CAP_DAC_READ_SEARCH capability to bypass an intended container protection mecha... Read more
Affected Products : vzkernel- EPSS Score: %0.09
- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGH- EPSS Score: %0.28
- Published: Dec. 13, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3484
Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 and 0.9.13 through 1.0.3 allow remote attackers to (1) have unspecified impact via an invalid name length in a DNS response or (2) caus... Read more
Affected Products : musl- EPSS Score: %1.79
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-3471
Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.... Read more
Affected Products : qemu- EPSS Score: %0.09
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024