Show filters
109 Total Results
Displaying 61-70 of 109
Sort by:
Attacker Value
Unknown

CVE-2014-3481

Disclosure Date: July 07, 2014 (last updated October 05, 2023)
org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown

CVE-2011-4111

Disclosure Date: February 26, 2014 (last updated October 05, 2023)
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC_ATR message.
0
Attacker Value
Unknown

CVE-2014-0058

Disclosure Date: February 26, 2014 (last updated October 05, 2023)
The security audit functionality in Red Hat JBoss Enterprise Application Platform (EAP) 6.x before 6.2.1 logs request parameters in plaintext, which might allow local users to obtain passwords by reading the log files.
0
Attacker Value
Unknown

CVE-2013-2185

Disclosure Date: January 19, 2014 (last updated November 08, 2023)
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue
0
Attacker Value
Unknown

CVE-2013-4424

Disclosure Date: December 23, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-5425

Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown

CVE-2012-4529

Disclosure Date: October 28, 2013 (last updated October 05, 2023)
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.
0
Attacker Value
Unknown

CVE-2013-4112

Disclosure Date: September 28, 2013 (last updated October 05, 2023)
The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.
0
Attacker Value
Unknown

CVE-2013-4128

Disclosure Date: August 16, 2013 (last updated October 05, 2023)
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
0
Attacker Value
Unknown

CVE-2013-4213

Disclosure Date: August 16, 2013 (last updated October 05, 2023)
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
0