VendorsRed Hatenterprise_mrg2.4
Vulnerabilities

Red Hat Redhat Enterprise MRG 2.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2013-4461
SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."
Published 2013-12-23 · Modified
7.5EPSS 0.019
CVE-2013-4405
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers to hijack the authentication of cumin users for unspecified requests.
Published 2013-12-23 · Modified
6.8EPSS 0.010
CVE-2013-4404
cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.
Published 2013-12-23 · Modified
6.5EPSS 0.019
CVE-2013-4345
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to improper management of the state of the consumed data.
Published 2013-10-10 · Modified
5.8EPSS 0.032
CVE-2013-4284
Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax update request.
Published 2013-10-09 · Modified
5.0EPSS 0.024
CVE-2013-4414
Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.
Published 2013-12-23 · Modified
4.3EPSS 0.018