Search CVE reports


Toggle filters

371 – 380 of 545 results


CVE-2014-3684

Medium priority

Some fixes available 2 of 4

The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted...

1 affected package

torque

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torque Not in release
Show less packages

CVE-2014-3558

Medium priority
Ignored

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute...

1 affected package

libhibernate-validator-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
libhibernate-validator-java Not affected
Show less packages

CVE-2014-6029

Medium priority
Ignored

TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.

1 affected package

torrentflux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torrentflux Not in release
Show less packages

CVE-2014-6028

Medium priority
Ignored

TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.

1 affected package

torrentflux

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torrentflux Not in release
Show less packages

CVE-2014-5191

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in the Preview plugin before 4.4.3 in CKEditor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

ckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ckeditor Not affected
Show less packages

CVE-2014-5117

Medium priority

Some fixes available 2 of 4

Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2014-4722

Medium priority
Vulnerable

Multiple cross-site scripting (XSS) vulnerabilities in the OCS Reports Web Interface in OCS Inventory NG allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

1 affected package

ocsinventory-server

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ocsinventory-server Not in release Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2014-4037

Medium priority
Ignored

Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitrary web script or HTML via an...

1 affected package

fckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fckeditor Not in release
Show less packages

CVE-2014-3004

Medium priority
Vulnerable

The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.

1 affected package

castor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
castor Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2014-0749

Medium priority

Some fixes available 2 of 4

Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.5.13 allows remote attackers to execute arbitrary code via a large count value.

1 affected package

torque

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torque Not in release
Show less packages