Оказание ИТ услуг Кемерово CVE-2014-0227

    java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.
      Теги:
    • нет
    • 0
    • 0
    • 0 комментариев

    Оказание ИТ услуг Кемерово CVE-2014-0154 (ovirt)

      oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
        Теги:
      • нет
      • 0
      • 0
      • 0 комментариев

      Оказание ИТ услуг Кемерово CVE-2013-2027 (jython, opensuse)

        Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
          Теги:
        • нет
        • 0
        • 0
        • 0 комментариев

        Оказание ИТ услуг Кемерово CVE-2015-0416 (supply_chain_products_suite)

          Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Roles & Privileges.
            Теги:
          • нет
          • 0
          • 0
          • 0 комментариев

          Оказание ИТ услуг Кемерово CVE-2015-0417 (siebel_crm)

            Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Portal Framework, a different vulnerability than CVE-2015-0388.
              Теги:
            • нет
            • 0
            • 0
            • 0 комментариев

            Оказание ИТ услуг Кемерово CVE-2015-0419 (siebel_crm)

              Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Portal Framework.
                Теги:
              • нет
              • 0
              • 0
              • 0 комментариев

              Оказание ИТ услуг Кемерово CVE-2015-0420 (fusion_middleware)

                Unspecified vulnerability in the Oracle Forms component in Oracle Fusion Middleware 11.1.1.7 and 11.1.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Forms Services.
                  Теги:
                • нет
                • 0
                • 0
                • 0 комментариев