258141
|
- |
|
theforeman
|
kafo
|
Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0135
|
2014-05-10 01:12 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258142
|
- |
|
dest-unreach
|
socat
|
socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor co…
|
NVD-CWE-noinfo
|
CVE-2013-3571
|
2014-05-9 23:00 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258143
|
- |
|
oracle
|
peoplesoft_products
|
Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect integrity via vectors related to PIA Core…
|
NVD-CWE-noinfo
|
CVE-2014-2443
|
2014-05-9 21:03 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258144
|
- |
|
theforeman
|
foreman
|
The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.
|
CWE-94
Code Injection
|
CVE-2013-0210
|
2014-05-9 00:29 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258145
|
- |
|
theforeman
|
foreman
|
Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0187
|
2014-05-9 00:00 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258146
|
- |
|
theforeman
|
foreman
|
Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attack.
|
CWE-310
Cryptographic Issues
|
CVE-2013-0173
|
2014-05-8 23:59 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258147
|
- |
|
theforeman
|
foreman
|
The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.
|
CWE-200
Information Exposure
|
CVE-2013-0174
|
2014-05-8 23:58 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258148
|
- |
|
theforeman
|
foreman
|
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
|
CWE-94
Code Injection
|
CVE-2013-0171
|
2014-05-8 23:52 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258149
|
- |
|
theforeman
|
foreman
|
The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-5477
|
2014-05-8 23:50 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258150
|
- |
|
illinois
|
ncsa_mosaic
|
NCSA Mosaic 2.1 through 2.7b5 allows local users to cause a denial of service ("remote control" outage) by creating a /tmp/Mosaic.pid file for every possible PID.
|
NVD-CWE-noinfo
|
CVE-2014-3426
|
2014-05-8 23:08 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|