CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass |
webauth before 4.6.1 has authentication credential disclosure |
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0. |
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host. |
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory. |
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names. |
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value. |
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository. |
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. |
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request. |
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New". |
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories. |
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks. |
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions. |
OpenStack nova base images permissions are world readable |
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords. |
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data. |
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. |
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack." |
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function |