258571
|
- |
|
emc
|
cloud_tiering_appliance_software cloud_tiering_appliance file_management_appliance_software file_management_appliance
|
EMC Cloud Tiering Appliance (CTA) 9.x through 10 SP1 and File Management Appliance (FMA) 7.x store DES password hashes for the root, super, and admin accounts, which makes it easier for context-depen…
|
CWE-255
Credentials Management
|
CVE-2014-0645
|
2014-04-18 00:10 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258572
|
- |
|
emc
|
cloud_tiering_appliance_software cloud_tiering_appliance
|
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity r…
|
CWE-200
Information Exposure
|
CVE-2014-0644
|
2014-04-18 00:06 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258573
|
- |
|
canonical
|
accountsservice ubuntu_linux
|
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4406
|
2014-04-17 23:33 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258574
|
- |
|
packagekit_project
|
packagekit
|
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1764
|
2014-04-17 23:30 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258575
|
- |
|
suse
|
kiwi studio_extension_for_system_z studio_onsite
|
kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in…
|
NVD-CWE-Other
|
CVE-2011-4195
|
2014-04-17 23:20 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258576
|
- |
|
suse
|
kiwi studio_extension_for_system_z studio_onsite
|
Per: https://cwe.mitre.org/data/definitions/77.html
"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')"
|
NVD-CWE-Other
|
CVE-2011-4195
|
2014-04-17 23:20 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258577
|
- |
|
bzip
|
bzip2
|
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by prec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4089
|
2014-04-17 23:15 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258578
|
- |
|
suse
|
studio_extension_for_system_z studio_onsite
|
Cross-site scripting (XSS) vulnerability in the overlay files tab in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1 allows remote attackers to inject arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2011-4193
|
2014-04-17 23:04 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258579
|
- |
|
suse
|
kiwi studio_extension_for_system_z studio_onsite
|
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double q…
|
NVD-CWE-Other
|
CVE-2011-4192
|
2014-04-17 22:53 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258580
|
- |
|
suse
|
kiwi studio_extension_for_system_z studio_onsite
|
Per: https://cwe.mitre.org/data/definitions/77.html
"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')"
|
NVD-CWE-Other
|
CVE-2011-4192
|
2014-04-17 22:53 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|