|
290331
|
- |
|
elfutils_project
|
elfutils
|
Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (ap…
|
CWE-189
Numeric Errors
|
CVE-2014-0172
|
2024-11-21 11:01 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290332
|
- |
|
fortinet
|
fortiadc_firmware fortiadc-1000e fortiadc-1500d fortiadc-2000d fortiadc-200d fortiadc-300e fortiadc-4000d fortiadc-400e fortiadc-600e
|
Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the locale param…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0331
|
2024-11-21 11:01 |
2014-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290333
|
- |
|
wordpress
|
wordpress
|
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it e…
|
CWE-287
Improper Authentication
|
CVE-2014-0166
|
2024-11-21 11:01 |
2014-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290334
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0165
|
2024-11-21 11:01 |
2014-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290335
|
- |
|
microsoft
|
windows_xp windows_server_2008 windows_server_2012 windows_rt windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8 windows_server_2003
|
Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows…
|
CWE-426
Untrusted Search Path
|
CVE-2014-0315
|
2024-11-21 11:01 |
2014-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290336
|
- |
|
huawei
|
echo_life_hg8247_firmware echo_life
|
Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2014-0337
|
2024-11-21 11:01 |
2014-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290337
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be gr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0093
|
2024-11-21 11:01 |
2014-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290338
|
- |
|
oracle apache
|
retail_applications tomcat commons_fileupload
|
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU co…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0050
|
2024-11-21 11:01 |
2014-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290339
|
- |
|
redhat
|
richfaces jboss_web_framework_kit
|
The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a…
|
CWE-20
Improper Input Validation
|
CVE-2014-0086
|
2024-11-21 11:01 |
2014-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290340
|
- |
|
apple postgresql
|
mac_os_x mac_os_x_server postgresql
|
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0067
|
2024-11-21 11:01 |
2014-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|