CVE-2014-2169
published 2014-05-02CVE-2014-2169: Cisco TelePresence TC Software 4.x through 6.x before 6.2.0 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using…
PriorityP349critical9CVSS 2.0
AVNACLAuSCCICAC
EPSS
2.09%
79.4th percentile
Cisco TelePresence TC Software 4.x through 6.x before 6.2.0 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to internal system scripts, aka Bug ID CSCue60211.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | telepresence_tc_and_te | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
| cisco | telepresence_tc_software | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv5.1MEDIUM
vendor_redhat7.8HIGH
vendor_cisco7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net/mlx5: DPLL, Fix possible use after free after delayed work timer triggers
vendor_redhat·2024-04-03·CVSS 7.8
CVE-2024-26724 [HIGH] CWE-416 kernel: net/mlx5: DPLL, Fix possible use after free after delayed work timer triggers
kernel: net/mlx5: DPLL, Fix possible use after free after delayed work timer triggers
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: DPLL, Fix possible use after free after delayed work timer triggers
I managed to hit following use after free warning recently:
[ 2169.711665] ==================================================================
[ 2169.714009] BUG: KASAN: slab-use-after-free in __run_timers.part.0+0x179/0x4c0
[ 2169.716293] Write of size 8 at addr ffff88812b326a70 by task swapper/4/0
[ 2169.719022] CPU: 4 PID: 0 Comm: swapper/4 Not tainted 6.8.0-rc2jiri+ #2
[ 2169.720974] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014
[ 2169.722457] Call Trace:
[ 2169.722756]
[ 2169.723024] dump_st
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco·2014-04-30·CVSS 7.5
CVE-2014-2162 [HIGH] CWE-119 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities:
Six Session Initiation Protocol (SIP) denial of service vulnerabilities
Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability
Cisco TelePresence TC and TE Software Input Validation Vulnerability
Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability
Cisco TelePresence TC and TE Software Heap Overflow Vulnerability
Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability
Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability
Cisco TelePresence TC H.225 Denial of Service Vulnerability
Successful exploitation of these vulnerabilities could allow an atta
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2169 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2169: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
GHSA
GHSA-jf76-7xpm-4gc7: Cisco TelePresence TC Software 4
ghsa_unreviewed·2022-05-17
CVE-2014-2169 [HIGH] CWE-20 GHSA-jf76-7xpm-4gc7: Cisco TelePresence TC Software 4
Cisco TelePresence TC Software 4.x through 6.x before 6.2.0 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to internal system scripts, aka Bug ID CSCue60211.
OSV
python-django regression
osv·2014-04-23·CVSS 5.1
CVE-2014-0472 python-django regression
python-django regression
USN-2169-1 fixed vulnerabilities in Django. The upstream security patch
for CVE-2014-0472 introduced a regression for certain applications. This
update fixes the problem.
Original advisory details:
Benjamin Bach discovered that Django incorrectly handled dotted Python
paths when using the reverse() function. An attacker could use this issue
to cause Django to import arbitrary modules from the Python path, resulting
in possible code execution. (CVE-2014-0472)
Paul McMillan discovered that Django incorrectly cached certain pages that
contained CSRF cookies. An attacker could possibly use this flaw to obtain
a valid cookie and perform attacks which bypass the CSRF restrictions.
(CVE-2014-0473)
Michael Koziarski discovered that Django did not always perform explic
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2014-05-02
Published