Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2018-1084

Disclosure Date: April 12, 2018 (last updated November 26, 2024)
corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
Attacker Value
Unknown

CVE-2015-5190

Disclosure Date: September 03, 2015 (last updated October 05, 2023)
The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.
0
Attacker Value
Unknown

CVE-2015-5189

Disclosure Date: September 03, 2015 (last updated October 05, 2023)
Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated.
0
Attacker Value
Unknown

CVE-2013-0250

Disclosure Date: June 06, 2014 (last updated October 05, 2023)
The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet.
0