Show filters
66 Total Results
Displaying 11-20 of 66
Sort by:
Attacker Value
Unknown
CVE-2020-14340
Disclosure Date: June 02, 2021 (last updated November 28, 2024)
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 through 3.8.1.Final.
0
Attacker Value
Unknown
CVE-2021-20191
Disclosure Date: May 26, 2021 (last updated December 29, 2023)
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when using those modules. An attacker can take advantage of this information to steal those credentials. The highest threat from this vulnerability is to data confidentiality. Versions before ansible 2.9.18 are affected.
0
Attacker Value
Unknown
CVE-2013-4535
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
0
Attacker Value
Unknown
CVE-2019-14859
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
0
Attacker Value
Unknown
CVE-2015-1780
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
0
Attacker Value
Unknown
CVE-2014-8167
Disclosure Date: November 13, 2019 (last updated November 27, 2024)
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
0
Attacker Value
Unknown
CVE-2013-4280
Disclosure Date: November 04, 2019 (last updated November 27, 2024)
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
0
Attacker Value
Unknown
CVE-2013-0186
Disclosure Date: November 01, 2019 (last updated November 27, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2019-10086
Disclosure Date: August 20, 2019 (last updated November 08, 2023)
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
0
Attacker Value
Unknown
CVE-2018-10928
Disclosure Date: September 04, 2018 (last updated November 27, 2024)
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server nodes.
0