|
285921
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_it360 manageengine_opmanager manageengine_applications_manager
|
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not proper…
|
CWE-200
Information Exposure
|
CVE-2014-7863
|
2024-11-21 11:18 |
2020-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285922
|
6.8 |
MEDIUM
Physics
|
tianocore
|
edk2
|
Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.
|
CWE-120
Classic Buffer Overflow
|
CVE-2014-8271
|
2024-11-21 11:18 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285923
|
5.3 |
MEDIUM
Network
|
dynamic_content_elements_project
|
dynamic_content_elements
|
The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the updat…
|
CWE-200
Information Exposure
|
CVE-2014-8328
|
2024-11-21 11:18 |
2020-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285924
|
7.8 |
HIGH
Local
|
unzip_project redhat
|
unzip enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_server_tus
|
Heap-based buffer overflow in the getZip64Data function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the un…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-8141
|
2024-11-21 11:18 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285925
|
6.1 |
MEDIUM
Network
|
videowhisper
|
webcam
|
Cross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhisper Webcam plugins for Drupal 7.x allows remote attackers to inject arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8338
|
2024-11-21 11:18 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285926
|
9.8 |
CRITICAL
Network
|
aircrack-ng
|
aircrack-ng
|
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
|
CWE-787
Out-of-bounds Write
|
CVE-2014-8322
|
2024-11-21 11:18 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285927
|
7.8 |
HIGH
Local
|
aircrack-ng
|
aircrack-ng
|
Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.
|
CWE-787
Out-of-bounds Write
|
CVE-2014-8321
|
2024-11-21 11:18 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285928
|
7.8 |
HIGH
Local
|
unzip_project redhat
|
unzip enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_server_tus
|
Heap-based buffer overflow in the test_compr_eb function in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the u…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-8140
|
2024-11-21 11:18 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285929
|
7.8 |
HIGH
Local
|
unzip_project redhat
|
unzip enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_server_tus
|
Heap-based buffer overflow in the CRC32 verification in Info-ZIP UnZip 6.0 and earlier allows remote attackers to execute arbitrary code via a crafted zip file in the -t command argument to the unzip…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-8139
|
2024-11-21 11:18 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285930
|
8.8 |
HIGH
Network
|
wisc
|
htcondor
|
The scheduler in HTCondor before 8.2.6 allows remote authenticated users to execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2014-8126
|
2024-11-21 11:18 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|