|
278921
|
- |
|
jasper_project
|
jasper
|
Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via…
|
CWE-189
Numeric Errors
|
CVE-2014-9029
|
2024-11-21 11:20 |
2014-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278922
|
- |
|
f5
|
big-ip
|
Cross-site scripting (XSS) vulnerability in the tree view (pl_tree.php) feature in Application Security Manager (ASM) in F5 BIG-IP 11.3.0 allows remote attackers to inject arbitrary web script or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9342
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278923
|
- |
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9219
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278924
|
- |
|
phpmyadmin
|
phpmyadmin
|
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long p…
|
CWE-399
Resource Management Errors
|
CVE-2014-9218
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278925
|
- |
|
torch_gmbh
|
graylog2
|
Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.
|
CWE-287
Improper Authentication
|
CVE-2014-9217
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278926
|
- |
|
plex
|
media_server
|
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9304
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278927
|
- |
|
entrypass
|
n5200_active_network_control_panel
|
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or…
|
CWE-200
Information Exposure
|
CVE-2014-9303
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278928
|
- |
|
alfresco
|
community_edition
|
Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attacke…
|
NVD-CWE-Other
|
CVE-2014-9302
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278929
|
- |
|
alfresco
|
alfresco
|
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger outbound requests to intranet servers, conduct port…
|
NVD-CWE-Other
|
CVE-2014-9301
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278930
|
- |
|
alfresco
|
alfresco
|
Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition before 5.0.a allows remote attackers to …
|
CWE-352
Origin Validation Error
|
CVE-2014-9300
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|