CVE-2017-7400

OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping.

CVE-2017-7401

Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with “SecurityLevel None” and with empty “AuthFile” options) via a crafted UDP packet.

CVE-2014-3928

Cougar-LG stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials.

CVE-2014-3929

The default configuration for Cougar-LG stores sensitive information under the web root with insufficient access control, which might allow remote attackers to obtain private ssh keys.

CVE-2014-3930

lg.pl in Cistron-LG 1.01 stores sensitive information under the web root with insufficient access controls, which allows remote attackers to obtain IP addresses and other unspecified router credentials.

CVE-2013-7450

Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.

CVE-2014-1677

Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.

CVE-2017-5951

The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.