Export limit exceeded: 86643 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (86643 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-0234 1 Redhat 1 Openshift 2024-11-21 9.8 Critical
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
CVE-2014-0183 1 Redhat 1 Subscription Asset Manager 2024-11-21 6.1 Medium
Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.
CVE-2014-0175 3 Debian, Puppet, Redhat 3 Debian Linux, Marionette Collective, Openshift 2024-11-21 9.8 Critical
mcollective has a default password set at install
CVE-2014-0163 1 Redhat 1 Openshift 2024-11-21 8.8 High
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
CVE-2014-0156 1 Manageiq 1 Awesomespawn 2024-11-21 9.8 Critical
Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command.
CVE-2014-0068 1 Redhat 2 Openshift, Openshift-origin-node-util 2024-11-21 5.5 Medium
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
CVE-2014-0014 1 Emberjs 1 Ember.js 2024-11-21 N/A
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application using the "{{group}}" Helper and a crafted payload.
CVE-2014-0013 1 Emberjs 1 Ember.js 2024-11-21 N/A
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templates whose context is set to a user-supplied primitive value and also contain the `{{this}}` special Handlebars variable.
CVE-2014-0011 1 Tigervnc 1 Tigervnc 2024-11-21 9.8 Critical
Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.
CVE-2013-7491 1 Perl 1 Dbi 2024-11-21 5.3 Medium
An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated.
CVE-2013-7487 1 Swann 8 Dvr-16cif, Dvr-16cif Firmware, Dvr04b and 5 more 2024-11-21 9.8 Critical
On Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote attackers to execute arbitrary code via TCP port 9000.
CVE-2013-7486 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x before 7.4.0-rev20 allows remote attackers to inject arbitrary web script or HTML via the body of an email. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of versions.
CVE-2013-7485 1 Open-xchange 1 Open-xchange Appsuite 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x before 7.4.0-rev16 allows remote attackers to inject arbitrary web script or HTML via the publication name, which is not properly handled in an error message. NOTE: this vulnerability was SPLIT from CVE-2013-6242 because it affects different sets of versions.
CVE-2013-7482 1 Reflex Gallery Project 1 Reflex Gallery 2024-11-21 N/A
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
CVE-2013-7481 1 Bestwebsoft 1 Contact Form 2024-11-21 N/A
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
CVE-2013-7480 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
CVE-2013-7479 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
CVE-2013-7478 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
CVE-2013-7477 1 Pixelite 1 Events Manager 2024-11-21 N/A
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
CVE-2013-7475 1 Bestwebsoft 1 Contact Form 2024-11-21 N/A
The contact-form-plugin plugin before 3.52 for WordPress has XSS.