|
287351
|
9.3 |
CRITICAL
Network
|
netgear
|
cg3100_firmware
|
A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3919
|
2024-11-21 11:09 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287352
|
7.8 |
HIGH
Local
|
xilisoft
|
video_converter
|
Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability
|
CWE-426
Untrusted Search Path
|
CVE-2014-3860
|
2024-11-21 11:09 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287353
|
8.8 |
HIGH
Network
|
zeuscart
|
zeuscart
|
Multiple SQL injection vulnerabilities in ZeusCart 4.x.
|
CWE-89
SQL Injection
|
CVE-2014-3868
|
2024-11-21 11:09 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287354
|
7.5 |
HIGH
Network
|
bytemark
|
symbiosis
|
Bytemark Symbiosis allows remote attackers to cause a denial of service via a crafted username, which triggers the firewall to blacklist the IP.
|
NVD-CWE-noinfo
|
CVE-2014-3979
|
2024-11-21 11:09 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287355
|
5.3 |
MEDIUM
Network
|
proxmox
|
virtual_environment
|
Proxmox VE prior to 3.2: 'AccessControl.pm' User Enumeration Vulnerability
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2014-4156
|
2024-11-21 11:09 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287356
|
9.8 |
CRITICAL
Network
|
apereo debian fedoraproject
|
.net_cas_client java_cas_client phpcas debian_linux fedora
|
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before…
|
CWE-74
Injection
|
CVE-2014-4172
|
2024-11-21 11:09 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287357
|
6.1 |
MEDIUM
Network
|
bssys
|
rbs_bs-client
|
Cross-site scripting (XSS) vulnerability in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allows remote attackers to inject arbitrary web script or HTML via the colorstyle parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4196
|
2024-11-21 11:09 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287358
|
6.1 |
MEDIUM
Network
|
ulli_horlacher
|
fex
|
The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to conduct cross-site scripting (XSS) attacks
|
CWE-79
Cross-site Scripting
|
CVE-2014-3875
|
2024-11-21 11:09 |
2019-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287359
|
5.5 |
MEDIUM
Local
|
s48
|
scheme48
|
The scheme48-send-definition function in cmuscheme48.el in Scheme 48 allows local users to write to arbitrary files via a symlink attack on /tmp/s48lose.tmp.
|
CWE-59
Link Following
|
CVE-2014-4150
|
2024-11-21 11:09 |
2018-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287360
|
8.1 |
HIGH
Network
|
horde
|
horde_ldap
|
The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.
|
CWE-287
Improper Authentication
|
CVE-2014-3999
|
2024-11-21 11:09 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|