|
277081
|
9.8 |
CRITICAL
Network
|
netsweeper
|
netsweeper
|
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via …
|
CWE-287
Improper Authentication
|
CVE-2014-9618
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277082
|
7.5 |
HIGH
Network
|
netsweeper
|
netsweeper
|
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that redirects to the deny page.
|
CWE-200
Information Exposure
|
CVE-2014-9616
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277083
|
9.8 |
CRITICAL
Network
|
netsweeper
|
netsweeper
|
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/index.php.
|
CWE-287
Improper Authentication
|
CVE-2014-9611
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277084
|
5.3 |
MEDIUM
Network
|
netsweeper
|
netsweeper
|
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the quarantine via the ip parameter to webadmin/user…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9610
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277085
|
5.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sen…
|
CWE-254
7PK - Security Features
|
CVE-2014-9635
|
2024-11-21 11:21 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277086
|
5.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmissi…
|
CWE-254
7PK - Security Features
|
CVE-2014-9634
|
2024-11-21 11:21 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277087
|
7.5 |
HIGH
Network
|
mantisbt
|
mantisbt
|
CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
|
CWE-287
Improper Authentication
|
CVE-2014-9624
|
2024-11-21 11:21 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277088
|
8.8 |
HIGH
Network
|
ibm
|
ib6131_firmware en6131_firmware
|
Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earlier.
|
CWE-352
Origin Validation Error
|
CVE-2014-9565
|
2024-11-21 11:21 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277089
|
7.5 |
HIGH
Network
|
mpg123
|
mpg123
|
Buffer overflow in mpg123 before 1.18.0.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9497
|
2024-11-21 11:21 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277090
|
9.8 |
CRITICAL
Network
|
smartcms
|
smartcms
|
Multiple SQL injection vulnerabilities in SmartCMS v.2.
|
CWE-89
SQL Injection
|
CVE-2014-9558
|
2024-11-21 11:21 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|