Show filters
28 Total Results
Displaying 1-10 of 28
Sort by:
Attacker Value
Unknown
CVE-2022-4780
Disclosure Date: December 29, 2022 (last updated November 08, 2023)
ISOS firmwares from versions 1.81 to 2.00 contain hardcoded credentials from embedded StreamX installer that integrators are not forced to change.
0
Attacker Value
Unknown
CVE-2022-2806
Disclosure Date: September 01, 2022 (last updated October 08, 2023)
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
0
Attacker Value
Unknown
CVE-2021-22777
Disclosure Date: July 21, 2021 (last updated November 28, 2024)
A CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause code execution by opening a malicious project file.
0
Attacker Value
Unknown
CVE-2020-15809
Disclosure Date: March 24, 2021 (last updated November 28, 2024)
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversal. This affects HMP350, HMP300, and DiVA through 4.5.2-1.0.36229; HMP400 and HMP400W through 4.5.2-1.0.2-1eb2ffbd; and DSOS through 4.5.2-1.0.2-1eb2ffbd.
0
Attacker Value
Unknown
CVE-2014-3445
Disclosure Date: January 28, 2020 (last updated February 21, 2025)
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.
0
Attacker Value
Unknown
CVE-2019-19750
Disclosure Date: September 18, 2019 (last updated May 01, 2024)
minerstat msOS before 2019-10-23 does not have a unique SSH key for each instance of the product.
0
Attacker Value
Unknown
CVE-2019-0204
Disclosure Date: March 25, 2019 (last updated November 08, 2023)
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.
0
Attacker Value
Unknown
CVE-2018-11793
Disclosure Date: March 05, 2019 (last updated November 08, 2023)
When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
0
Attacker Value
Unknown
CVE-2019-5736
Disclosure Date: February 11, 2019 (last updated November 08, 2023)
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
0
Attacker Value
Unknown
CVE-2018-1000421
Disclosure Date: January 09, 2019 (last updated November 08, 2023)
An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
0