Show filters
129 Total Results
Displaying 71-80 of 129
Sort by:
Attacker Value
Unknown

CVE-2019-0204

Disclosure Date: March 25, 2019 (last updated November 08, 2023)
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.
Attacker Value
Unknown

CVE-2018-19760

Disclosure Date: November 30, 2018 (last updated November 27, 2024)
cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.
0
Attacker Value
Unknown

CVE-2016-8653

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
It was found that the JMX endpoint of Red Hat JBoss Fuse 6, and Red Hat A-MQ 6 deserializes the credentials passed to it. An attacker could use this flaw to launch a denial of service attack.
0
Attacker Value
Unknown

CVE-2016-8648

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
It was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via JMX operations. An attacker could use this flaw to execute remote code on the server as the user running the Java Virtual Machine if the target MBean contain deserialization gadgets in its classpath.
0
Attacker Value
Unknown

CVE-2017-2589

Disclosure Date: July 26, 2018 (last updated November 27, 2024)
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
0
Attacker Value
Unknown

CVE-2018-10906

Disclosure Date: July 24, 2018 (last updated November 08, 2023)
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.
0
Attacker Value
Unknown

CVE-2018-14447

Disclosure Date: July 20, 2018 (last updated November 27, 2024)
trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2016-10576

Disclosure Date: June 01, 2018 (last updated November 26, 2024)
Fuseki server wrapper and management API in fuseki before 1.0.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2018-1258

Disclosure Date: May 11, 2018 (last updated November 26, 2024)
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
Attacker Value
Unknown

CVE-2017-12196

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
0