Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2019-14905

Disclosure Date: March 31, 2020 (last updated February 21, 2025)
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
Attacker Value
Unknown

CVE-2019-14864

Disclosure Date: January 02, 2020 (last updated February 21, 2025)
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
Attacker Value
Unknown

CVE-2014-0197

Disclosure Date: December 13, 2019 (last updated November 27, 2024)
CFME: CSRF protection vulnerability via permissive check of the referrer header
Attacker Value
Unknown

CVE-2013-6461

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Attacker Value
Unknown

CVE-2013-6460

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Attacker Value
Unknown

CVE-2014-7813

Disclosure Date: October 18, 2017 (last updated November 26, 2024)
Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors involving calls to the .to_sym rails function and lack of garbage collection of inserted symbols.
0
Attacker Value
Unknown

CVE-2014-0136

Disclosure Date: October 27, 2014 (last updated October 05, 2023)
The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text into log files via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-3642

Disclosure Date: October 06, 2014 (last updated October 05, 2023)
vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to gain privileges via unspecified vectors, related to an "insecure send method."
0
Attacker Value
Unknown

CVE-2014-0140

Disclosure Date: October 06, 2014 (last updated October 05, 2023)
Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to access sensitive controllers and actions via a direct HTTP or HTTPS request.
0
Attacker Value
Unknown

CVE-2014-3486

Disclosure Date: July 07, 2014 (last updated October 05, 2023)
The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.
0