| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 16 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 15 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 14 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 13 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 9 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46). |
| Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46). |
| The default cloud-init configuration, in cloud-init 0.6.2 and newer, included "ssh_deletekeys: 0", disabling cloud-init's deletion of ssh host keys. In some environments, this could lead to instances created by cloning a golden master or template system, sharing ssh host keys, and being able to impersonate one another or conduct man-in-the-middle attacks. |
| The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness. |
| A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code. |
| In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result. |