CVE-2019-16892
- EPSS 0.24%
- Published 25.09.2019 22:15:10
- Last modified 21.11.2024 04:31:17
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
CVE-2019-10159
- EPSS 0.22%
- Published 14.06.2019 14:29:00
- Last modified 21.11.2024 04:18:32
cfme-gemset versions 5.10.4.3 and below, 5.9.9.3 and below are vulnerable to a data leak, due to an improper authorization in the migration log controller. An attacker with access to an unprivileged user can access all VM migration logs available.
CVE-2019-11358
- EPSS 2.4%
- Published 20.04.2019 00:29:00
- Last modified 21.11.2024 04:20:56
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the n...
CVE-2019-5419
- EPSS 9.06%
- Published 27.03.2019 14:29:01
- Last modified 21.11.2024 04:44:54
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
CVE-2019-5418
- EPSS 94.32%
- Published 27.03.2019 14:29:01
- Last modified 09.07.2025 15:23:23
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
CVE-2018-16476
- EPSS 0.82%
- Published 30.11.2018 19:29:00
- Last modified 21.11.2024 03:52:49
A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability...
- EPSS 3.11%
- Published 31.10.2018 13:29:00
- Last modified 21.11.2024 02:54:14
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as the user C...
CVE-2016-7047
- EPSS 0.33%
- Published 11.09.2018 13:29:00
- Last modified 21.11.2024 02:57:21
A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.
- EPSS 0.5%
- Published 10.09.2018 15:29:00
- Last modified 21.11.2024 02:57:24
It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they...
CVE-2017-2632
- EPSS 0.4%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:52
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administr...