Show filters
79 Total Results
Displaying 61-70 of 79
Sort by:
Attacker Value
Unknown

CVE-2016-8103

Disclosure Date: December 08, 2016 (last updated November 25, 2024)
SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.
0
Attacker Value
Unknown

CVE-2016-0738

Disclosure Date: January 29, 2016 (last updated November 25, 2024)
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
0
Attacker Value
Unknown

CVE-2016-0737

Disclosure Date: January 29, 2016 (last updated November 25, 2024)
OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
0
Attacker Value
Unknown

CVE-2015-8466

Disclosure Date: January 13, 2016 (last updated November 25, 2024)
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
0
Attacker Value
Unknown

CVE-2015-5223

Disclosure Date: October 26, 2015 (last updated October 05, 2023)
OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container.
0
Attacker Value
Unknown

CVE-2015-4641

Disclosure Date: June 19, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in the SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices allows remote web servers to write to arbitrary files, and consequently execute arbitrary code in a privileged context, by leveraging control of the skslm.swiftkey.net domain name and providing a .. (dot dot) in an entry in a ZIP archive, as demonstrated by a traversal to the /data/dalvik-cache directory.
0
Attacker Value
Unknown

CVE-2015-4640

Disclosure Date: June 19, 2015 (last updated October 05, 2023)
The SwiftKey language-pack update implementation on Samsung Galaxy S4, S4 Mini, S5, and S6 devices relies on an HTTP connection to the skslm.swiftkey.net server, which allows man-in-the-middle attackers to write to language-pack files by modifying an HTTP response. NOTE: CVE-2015-4640 exploitation can be combined with CVE-2015-4641 exploitation for man-in-the-middle code execution.
0
Attacker Value
Unknown

CVE-2015-1856

Disclosure Date: April 17, 2015 (last updated October 05, 2023)
OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.
0
Attacker Value
Unknown

CVE-2014-7960

Disclosure Date: October 17, 2014 (last updated October 05, 2023)
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
0
Attacker Value
Unknown

CVE-2014-5722

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The SwiftKey Keyboard + Emoji (aka com.touchtype.swiftkey) application 5.0.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0