CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Openstack2Image Registry And Delivery Service (glance) Ubuntu LinuxMay 6, 2026 Aug 25, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allo...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxMay 6, 2026 Aug 25, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped t...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxMay 6, 2026 Aug 25, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and ret...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxMay 6, 2026 Aug 25, 2014 N/A· v4 N/A· v3 4.9 MEDIUM· v2 The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allo...Show more |
3Canonical DebianKde4Kauth Kde4libsKdelibs+1 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess Polkit...Show more |
3Canonical OpenstackRedhat6Neutron OpenstackOslo+3 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authe...Show more |
5Apache AppleCanonical+2 more9Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Server+6 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credent...Show more |
4Apache AppleCanonical+1 more4Opensuse SubversionUbuntu Linux+1 moreMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows m...Show more |
3Apache CanonicalSerf Project3Serf SubversionUbuntu LinuxMay 6, 2026 Aug 19, 2014 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common N...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Aug 18, 2014 N/A· v4 N/A· v3 6.2 MEDIUM· v2 fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain p...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Aug 18, 2014 N/A· v4 N/A· v3 7.2 HIGH· v2 The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restrict...Show more |
3Canonical RedhatSamba3Enterprise Linux SambaUbuntu LinuxMay 6, 2026 Aug 6, 2014 N/A· v4 N/A· v3 7.9 HIGH· v2 NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on...Show more |
4Canonical LinuxRedhat+1 more8Enterprise Linux Eus Enterprise Linux Server AusEnterprise Linux Server Tus+5 moreMay 6, 2026 Aug 1, 2014 N/A· v4 N/A· v3 7.1 HIGH· v2 The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by...Show more |
The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors. |
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py. |
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of a...Show more |
4Canonical FedoraprojectGentoo+1 more4Fedora LinuxTransmission+1 moreMay 6, 2026 Jul 29, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer messag...Show more |
Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors. |
3Apple CanonicalFedoraproject3Cups FedoraUbuntu LinuxMay 6, 2026 Jul 23, 2014 N/A· v4 N/A· v3 1.2 LOW· v2 The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/. |
2Canonical Openstack2Neutron Ubuntu LinuxMay 6, 2026 Jul 11, 2014 N/A· v4 N/A· v3 3.5 LOW· v2 The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 priva...Show more |