Show filters
59 Total Results
Displaying 31-40 of 59
Sort by:
Attacker Value
Unknown

CVE-2019-19921

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)
Attacker Value
Unknown

CVE-2013-2060

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.
Attacker Value
Unknown

CVE-2014-0175

Disclosure Date: December 13, 2019 (last updated November 27, 2024)
mcollective has a default password set at install
Attacker Value
Unknown

CVE-2014-0163

Disclosure Date: December 11, 2019 (last updated November 27, 2024)
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
Attacker Value
Unknown

CVE-2013-0163

Disclosure Date: December 05, 2019 (last updated November 27, 2024)
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
Attacker Value
Unknown

CVE-2013-2103

Disclosure Date: December 03, 2019 (last updated November 27, 2024)
OpenShift cartridge allows remote URL retrieval
Attacker Value
Unknown

CVE-2019-10174

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Attacker Value
Unknown

CVE-2012-6135

Disclosure Date: November 19, 2019 (last updated November 27, 2024)
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
Attacker Value
Unknown

CVE-2019-10219

Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Attacker Value
Unknown

CVE-2013-5123

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.