CVE-2013-2166: python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Published Dec 10, 2019 · Updated Aug 6, 2024
Browse CVE records published in December 2013, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 47 of 547 matching CVEs · Page 11 of 11.
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Published Dec 10, 2019 · Updated Aug 6, 2024
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.
Published Dec 6, 2013 · Updated Aug 6, 2024
webauth before 4.6.1 has authentication credential disclosure
Published Dec 3, 2019 · Updated Aug 6, 2024
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
Published Dec 10, 2019 · Updated Aug 6, 2024
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection
Published Dec 10, 2019 · Updated Aug 6, 2024
OpenShift cartridge allows remote URL retrieval
Published Dec 3, 2019 · Updated Aug 6, 2024
Katello has multiple XSS issues in various entities
Published Dec 3, 2019 · Updated Aug 6, 2024
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
Published Dec 27, 2013 · Updated Aug 6, 2024
Integer underflow in the input_bmp_reader function in input-bmp.c in AutoTrace 0.31.1 allows context-dependent attackers to have an unspecified impact via a small value in the biSize field in the header of a BMP file, which triggers a buffer overflow.
Published Dec 9, 2013 · Updated Aug 6, 2024
Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.
Published Dec 12, 2013 · Updated Aug 6, 2024
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus increase their privileges on the host.
Published Dec 30, 2019 · Updated Aug 6, 2024
WordPress W3 Super Cache Plugin before 1.3.2 contains a PHP code-execution vulnerability which could allow remote attackers to inject arbitrary code. This issue exists because of an incomplete fix for CVE-2013-2009.
Published Dec 26, 2019 · Updated Aug 6, 2024
Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.
Published Dec 12, 2013 · Updated Aug 6, 2024
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
Published Dec 12, 2013 · Updated Aug 6, 2024
openstack-utils openstack-db has insecure password creation
Published Dec 10, 2019 · Updated Aug 6, 2024
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.
Published Dec 10, 2019 · Updated Aug 6, 2024
OpenJPEG 1.3 and earlier allows remote attackers to cause a denial of service (memory consumption or crash) via unspecified vectors related to NULL pointer dereferences, division-by-zero, and other errors.
Published Dec 12, 2013 · Updated Aug 6, 2024
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.
Published Dec 16, 2016 · Updated Aug 6, 2024
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.
Published Dec 9, 2013 · Updated Aug 6, 2024
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
Published Dec 14, 2013 · Updated Aug 6, 2024
The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, which allows local wwwrun users to gain privileges via unspecified vectors.
Published Dec 6, 2013 · Updated Aug 6, 2024
Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.
Published Dec 28, 2013 · Updated Aug 6, 2024
The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.
Published Dec 7, 2013 · Updated Aug 6, 2024
The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in huffyuv data with the predictor set to median and the colorspace set to YUV422P, which triggers an out-of-bounds array access.
Published Dec 7, 2013 · Updated Aug 6, 2024
The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-bounds array access.
Published Dec 7, 2013 · Updated Aug 6, 2024
The parse_picture_segment function in libavcodec/pgssubdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted RLE data, which triggers an out-of-bounds array access.
Published Dec 7, 2013 · Updated Aug 6, 2024
The add_doubles_metadata function in libavcodec/tiff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a negative or zero count value in a TIFF image, which triggers an out-of-bounds array access.
Published Dec 7, 2013 · Updated Aug 6, 2024
The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, related to a large nb_samples value.
Published Dec 7, 2013 · Updated Aug 6, 2024
The mjpeg_decode_scan_progressive_ac function in libavcodec/mjpegdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted MJPEG data.
Published Dec 7, 2013 · Updated Aug 6, 2024
The wavpack_decode_frame function in libavcodec/wavpack.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted WavPack data, which triggers an out-of-bounds array access, possibly due to an off-by-one error.
Published Dec 7, 2013 · Updated Aug 6, 2024
The ff_id3v2_parse function in libavformat/id3v2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via ID3v2 header data, which triggers an out-of-bounds array access.
Published Dec 7, 2013 · Updated Aug 6, 2024
Off-by-one error in the adpcm_decode_frame function in libavcodec/adpcm.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via crafted DK4 data, which triggers an out-of-bounds array access.
Published Dec 7, 2013 · Updated Aug 6, 2024
The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted H.264 data, which triggers an out-of-bounds array access.
Published Dec 7, 2013 · Updated Aug 6, 2024
The decode_frame_ilbm function in libavcodec/iff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted height value in IFF PBM/ILBM bitmap data.
Published Dec 7, 2013 · Updated Aug 6, 2024
Integer overflow in the alac_decode_close function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a large number of samples per frame in Apple Lossless Audio Codec (ALAC) data, which triggers an out-of-bounds array access.
Published Dec 7, 2013 · Updated Aug 6, 2024
Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted QDM2 data, which triggers an out-of-bounds array access.
Published Dec 7, 2013 · Updated Aug 6, 2024
libavcodec/alsdec.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via a crafted block length, which triggers an out-of-bounds write.
Published Dec 7, 2013 · Updated Aug 6, 2024
The roq_decode_init function in libavcodec/roqvideodec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted (1) width or (2) height dimension that is not a multiple of sixteen in id RoQ video data.
Published Dec 7, 2013 · Updated Aug 6, 2024
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
Published Dec 9, 2019 · Updated Aug 6, 2024
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
Published Dec 13, 2013 · Updated Aug 6, 2024
OpenStack nova base images permissions are world readable
Published Dec 5, 2019 · Updated Aug 6, 2024
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
Published Dec 10, 2019 · Updated Aug 6, 2024
Katello: Username in Notification page has cross site scripting
Published Dec 5, 2019 · Updated Aug 6, 2024
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections
Published Dec 5, 2019 · Updated Aug 6, 2024
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.
Published Dec 30, 2019 · Updated Aug 6, 2024
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.
Published Dec 30, 2019 · Updated Aug 6, 2024
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
Published Dec 5, 2019 · Updated Aug 6, 2024