Show filters
58 Total Results
Displaying 21-30 of 58
Sort by:
Attacker Value
Unknown
Garden-runC prevents deletion of some app environments
Disclosure Date: September 18, 2018 (last updated November 27, 2024)
Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps.
0
Attacker Value
Unknown
CVE-2018-14448
Disclosure Date: July 20, 2018 (last updated November 27, 2024)
Codec::parse in track.cpp in Untrunc through 2018-06-07 has a NULL pointer dereference via a crafted MP4 file because of improper interaction with libav.
0
Attacker Value
Unknown
CVE-2018-1277
Disclosure Date: April 30, 2018 (last updated November 26, 2024)
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.
0
Attacker Value
Unknown
CVE-2018-1191
Disclosure Date: March 29, 2018 (last updated November 26, 2024)
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.
0
Attacker Value
Unknown
CVE-2016-3697
Disclosure Date: June 01, 2016 (last updated November 25, 2024)
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
0
Attacker Value
Unknown
CVE-2015-1614
Disclosure Date: February 19, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) image_metadata_cruncher[alt] or (2) image_metadata_cruncher[caption] parameter in an update action in the image_metadata_cruncher_title page to wp-admin/options.php or (3) custom image meta tag to the image metadata cruncher page.
0
Attacker Value
Unknown
CVE-2010-2852
Disclosure Date: July 25, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in modules/headlines/magpierss/scripts/magpie_debug.php in RunCms 2.1, when the Headlines module is enabled, allows remote attackers to inject arbitrary web script or HTML via the url parameter.
0
Attacker Value
Unknown
CVE-2009-3804
Disclosure Date: October 27, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.
0
Attacker Value
Unknown
CVE-2009-3814
Disclosure Date: October 27, 2009 (last updated October 04, 2023)
Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" feature, as demonstrated by modifying modules/system/cache/bademails.php using the "Prohibited: Emails" action, and other unspecified filters.
0
Attacker Value
Unknown
CVE-2009-3813
Disclosure Date: October 27, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter to modules/forum/post.php and possibly (2) forum_id variable to modules/forum/class/class.permissions.php.
0