Show filters
59 Total Results
Displaying 51-59 of 59
Sort by:
Attacker Value
Unknown
CVE-2019-5736
Disclosure Date: February 11, 2019 (last updated November 08, 2023)
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
0
Attacker Value
Unknown
CVE-2013-4364
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
0
Attacker Value
Unknown
CVE-2015-5250
Disclosure Date: September 08, 2015 (last updated October 05, 2023)
The API server in OpenShift Origin 1.0.5 allows remote attackers to cause a denial of service (master process crash) via crafted JSON data.
0
Attacker Value
Unknown
CVE-2014-1869
Disclosure Date: February 08, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters (aka loaderInfo.parameters).
0
Attacker Value
Unknown
CVE-2013-2119
Disclosure Date: January 03, 2014 (last updated October 05, 2023)
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
0
Attacker Value
Unknown
CVE-2012-5658
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.
0
Attacker Value
Unknown
CVE-2013-0164
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
0
Attacker Value
Unknown
CVE-2012-5647
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO.
0
Attacker Value
Unknown
CVE-2012-5646
Disclosure Date: February 24, 2013 (last updated October 05, 2023)
node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO.
0