Show filters
177 Total Results
Displaying 161-170 of 177
Sort by:
Attacker Value
Unknown
CVE-2016-0927
Disclosure Date: September 18, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2016-6639
Disclosure Date: September 18, 2016 (last updated November 25, 2024)
Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file.
0
Attacker Value
Unknown
CVE-2016-0930
Disclosure Date: September 18, 2016 (last updated November 25, 2024)
Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist.
0
Attacker Value
Unknown
CVE-2016-0929
Disclosure Date: September 18, 2016 (last updated November 25, 2024)
The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.
0
Attacker Value
Unknown
CVE-2016-0926
Disclosure Date: September 18, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.
0
Attacker Value
Unknown
CVE-2016-0928
Disclosure Date: September 18, 2016 (last updated November 25, 2024)
Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-3192
Disclosure Date: July 12, 2016 (last updated November 25, 2024)
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
0
Attacker Value
Unknown
CVE-2015-0201
Disclosure Date: March 10, 2015 (last updated October 05, 2023)
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-3578
Disclosure Date: February 19, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
0
Attacker Value
Unknown
CVE-2014-9494
Disclosure Date: January 20, 2015 (last updated October 05, 2023)
RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.
0