Show filters
81 Total Results
Displaying 41-50 of 81
Sort by:
Attacker Value
Unknown
CVE-2013-4405
Disclosure Date: December 23, 2013 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers to hijack the authentication of cumin users for unspecified requests.
0
Attacker Value
Unknown
CVE-2013-4404
Disclosure Date: December 23, 2013 (last updated October 05, 2023)
cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-4414
Disclosure Date: December 23, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.
0
Attacker Value
Unknown
CVE-2013-4461
Disclosure Date: December 23, 2013 (last updated October 05, 2023)
SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."
0
Attacker Value
Unknown
CVE-2013-4255
Disclosure Date: October 11, 2013 (last updated October 05, 2023)
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
0
Attacker Value
Unknown
CVE-2009-5136
Disclosure Date: October 11, 2013 (last updated October 05, 2023)
The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
0
Attacker Value
Unknown
CVE-2013-4345
Disclosure Date: October 10, 2013 (last updated October 05, 2023)
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to improper management of the state of the consumed data.
0
Attacker Value
Unknown
CVE-2013-4284
Disclosure Date: October 09, 2013 (last updated October 05, 2023)
Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax update request.
0
Attacker Value
Unknown
CVE-2013-1892
Disclosure Date: October 01, 2013 (last updated October 05, 2023)
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument.
0
Attacker Value
Unknown
CVE-2013-1909
Disclosure Date: August 23, 2013 (last updated October 05, 2023)
The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
0