NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 84650 | CVE-2017-4964 | Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the director, aka a CPI code injection vulnerability. | 2 | 4.6 | Medium | 2017-04-27 | 2017-04-12 | View | |
| 86350 | CVE-2016-0761 | Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host. | 2 | 10 | High | 2017-06-12 | 2017-06-08 | View | |
| 21321 | CVE-2016-6639 | Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file. | 2 | 5 | Medium | 2017-01-19 | 2016-09-19 | View | |
| 83890 | CVE-2015-4166 | Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors related to loss of an encryption key. | 2 | 7.5 | High | 2017-03-29 | 2017-03-27 | View | |
| 44055 | CVE-2012-2230 | Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller.cfg, which allows remote authenticated users to impersonate arbitrary user accounts via unspecified vectors, a different vulnerability than CVE-2012-1574. | 2 | 6.5 | Medium | 2017-01-19 | 2012-11-19 | View |
Page 2597 of 17672, showing 5 records out of 88360 total, starting on record 12981, ending on 12985