Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2022-2806
Disclosure Date: September 01, 2022 (last updated October 08, 2023)
It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev
0
Attacker Value
Unknown
CVE-2018-14650
Disclosure Date: September 27, 2018 (last updated November 27, 2024)
It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting for a legit user to run sos-collector and steal the collected data in the /var/tmp directory.
0
Attacker Value
Unknown
CVE-2015-7529
Disclosure Date: November 06, 2017 (last updated November 26, 2024)
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$hostname-$date.
0
Attacker Value
Unknown
CVE-2015-3171
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
sosreport 3.2 uses weak permissions for generated sosreport archives, which allows local users with access to /var/tmp/ to obtain sensitive information by reading the contents of the archive.
0
Attacker Value
Unknown
CVE-2014-7436
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The SOS recette (aka com.sos.recette) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6694
Disclosure Date: September 24, 2014 (last updated October 05, 2023)
The 5SOS Family Planet (aka uk.co.pixelkicks.fivesos) application 2.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0