|
278801
|
- |
|
scalix
|
web_access
|
XML external entity (XXE) vulnerability in Scalix Web Access 11.4.6.12377 and 12.2.0.14697 allows remote attackers to read arbitrary files and trigger requests to intranet servers via a crafted reque…
|
NVD-CWE-Other
|
CVE-2014-9360
|
2024-11-21 11:20 |
2014-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278802
|
- |
|
intelliants
|
subrion
|
Cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to subrion/search/.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9120
|
2024-11-21 11:20 |
2014-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278803
|
- |
|
icecast
|
icecast
|
Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9091
|
2024-11-21 11:20 |
2014-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278804
|
- |
|
scalix
|
web_access
|
Cross-site scripting (XSS) vulnerability in the mail administration login panel in Scalix Web Access 11.4.6.12377 allows remote attackers to inject arbitrary web script or HTML via unspecified vector…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9352
|
2024-11-21 11:20 |
2014-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278805
|
- |
|
teeworlds
|
teeworlds
|
engine/server/server.cpp in Teeworlds 0.6.x before 0.6.3 allows remote attackers to read memory and cause a denial of service (crash) via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2014-9351
|
2024-11-21 11:20 |
2014-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278806
|
- |
|
ffmpeg
|
ffmpeg
|
The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds acc…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9319
|
2024-11-21 11:20 |
2014-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278807
|
- |
|
ffmpeg
|
ffmpeg
|
The raw_decode function in libavcodec/rawdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9318
|
2024-11-21 11:20 |
2014-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278808
|
- |
|
ffmpeg
|
ffmpeg
|
The decode_ihdr_chunk function in libavcodec/pngdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap acce…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9317
|
2024-11-21 11:20 |
2014-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278809
|
- |
|
ffmpeg
|
ffmpeg
|
The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap acc…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9316
|
2024-11-21 11:20 |
2014-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278810
|
- |
|
mantisbt
|
mantisbt
|
Cross-site scripting (XSS) vulnerability in admin/copy_field.php in MantisBT before 1.2.18 allows remote attackers to inject arbitrary web script or HTML via the dest_id field.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9281
|
2024-11-21 11:20 |
2014-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|