Vulnerabilities (CVE)

Vendor filter

Novell Subscribe

Filter

1545 total CVE
CVE Vendors Products Updated CVSS
CVE-2014-7829 3 Rubyonrails, Novell, Opensuse 4 Ruby On Rails, Opensuse, Opensuse and 1 more 2019-08-08 5.0
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is...
CVE-2014-7818 3 Rubyonrails, Novell, Opensuse 4 Ruby On Rails, Opensuse, Opensuse and 1 more 2019-08-08 4.3
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is...
CVE-2015-3227 3 Rubyonrails, Novell, Opensuse 4 Ruby On Rails, Opensuse, Opensuse and 1 more 2019-08-08 5.0
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service (SystemStackError) via a large XML document depth.
CVE-2013-0334 4 Bundler, Fedoraproject, Novell and 1 more 4 Fedora, Bundler, Opensuse and 1 more 2019-07-16 5.0
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
CVE-2013-3567 4 Puppetlabs, Canonical, Novell and 1 more 6 Ubuntu Linux, Suse Linux Enterprise Desktop, Puppet and 3 more 2019-07-10 7.5
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
CVE-2012-3867 7 Suse, Puppetlabs, Debian and 4 more 9 Ubuntu Linux, Linux Enterprise Desktop, Debian Linux and 6 more 2019-07-10 4.3
lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Certificate Signing Request (CSR), which makes it...
CVE-2014-3637 3 D-bus Project, Novell, Opensuse 3 D-bus, Opensuse, Opensuse 2019-06-24 2.1
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descriptor.
CVE-2014-9761 6 Gnu, Suse, Fedoraproject and 3 more 10 Linux Enterprise Software Development Kit, Ubuntu Linux, Linux Enterprise Desktop and 7 more 2019-06-13 7.5
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan,...
CVE-2014-9402 4 Gnu, Canonical, Novell and 1 more 4 Ubuntu Linux, Glibc, Opensuse and 1 more 2019-06-13 7.8
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a...
CVE-2014-4043 3 Gnu, Novell, Opensuse 3 Glibc, Opensuse, Opensuse 2019-06-13 7.5
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
CVE-2016-1234 4 Fedoraproject, Gnu, Novell and 1 more 5 Glibc, Fedora, Opensuse and 2 more 2019-05-31 5.0
Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name.
CVE-2016-5760 1 Novell 1 Groupwise 2019-05-30 4.3
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to...
CVE-2016-5761 1 Novell 1 Groupwise 2019-05-30 4.3
Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email.
CVE-2016-5762 1 Novell 1 Groupwise 2019-05-30 7.5
Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.
CVE-2016-0611 5 Novell, Oracle, Canonical and 2 more 7 Ubuntu Linux, Leap, Enterprise Linux and 4 more 2019-05-01 4.0
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
CVE-2017-1000366 9 Gnu, Redhat, Suse and 6 more 24 Glibc, Enterprise Linux, Linux Enterprise Server For Raspberry Pi and 21 more 2019-04-26 7.2
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been...
CVE-2014-7926 8 Google, Icu Project, Oracle and 5 more 11 Ubuntu Linux, International Components For Unicode, Enterprise Linux Desktop Supplementary and 8 more 2019-04-23 7.5
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have...
CVE-2014-7923 8 Google, Icu Project, Oracle and 5 more 11 Ubuntu Linux, International Components For Unicode, Enterprise Linux Desktop Supplementary and 8 more 2019-04-23 7.5
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have...
CVE-2016-0646 7 Oracle, Redhat, Ibm and 4 more 8 Leap, Linux, Debian Linux and 5 more 2019-04-22 4.0
Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DML.
CVE-2013-0221 4 Gnu, Novell, Redhat and 1 more 4 Coreutils, Enterprise Linux, Opensuse and 1 more 2019-04-22 4.3
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch, which triggers a...