Security Bulletins
Latest Malware Updates
|
11/03/2014
CVE-2014-8080
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.
Attack vector:
Network
Product:
-
ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- ruby-lang: ruby
- canonical: ubuntu_linux
- canonical: ubuntu_linux
- canonical: ubuntu_linux
- redhat: enterprise_linux
- redhat: enterprise_linux
- novell: opensuse
- novell: opensuse
References:
Severity:
Medium
CVSS Score:
5.0
CVSS Vector:
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
|
Security Advisories Database
A remote attacker can execute arbitrary code on the target system.
07/21/2015
SQL inection vulnerability has been discovered in Piwigo.
02/05/2015
A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.
02/05/2015
A cross-site scripting vulnerability was found in Hitachi Command Suite.
02/02/2015
An attacker can perform a denial of service attack.
01/30/2015
An attacker can perform a denial of service attack.
01/30/2015
An attacker can perform a denial of service attack.
01/30/2015
An attacker can perform a denial of service attack.
01/29/2015
An attacker can perform a denial of service attack.
01/20/2015
|