Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2019-14905
Disclosure Date: March 31, 2020 (last updated February 21, 2025)
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
0
Attacker Value
Unknown
CVE-2019-14864
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
0
Attacker Value
Unknown
CVE-2014-0197
Disclosure Date: December 13, 2019 (last updated November 27, 2024)
CFME: CSRF protection vulnerability via permissive check of the referrer header
0
Attacker Value
Unknown
CVE-2013-6461
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
0
Attacker Value
Unknown
CVE-2013-6460
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
0
Attacker Value
Unknown
CVE-2013-4423
Disclosure Date: November 04, 2019 (last updated November 27, 2024)
CloudForms stores user passwords in recoverable format
0
Attacker Value
Unknown
CVE-2013-0186
Disclosure Date: November 01, 2019 (last updated November 27, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-7813
Disclosure Date: October 18, 2017 (last updated November 26, 2024)
Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors involving calls to the .to_sym rails function and lack of garbage collection of inserted symbols.
0
Attacker Value
Unknown
CVE-2014-0136
Disclosure Date: October 27, 2014 (last updated October 05, 2023)
The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text into log files via unspecified vectors.
0
Attacker Value
Unknown
CVE-2014-3642
Disclosure Date: October 06, 2014 (last updated October 05, 2023)
vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to gain privileges via unspecified vectors, related to an "insecure send method."
0