|
276971
|
- |
|
mediawiki
|
mediawiki
|
The wfMangleFlashPolicy function in OutputHandler.php in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7 allows remote attackers to conduct PHP object injecti…
|
CWE-77
Command Injection
|
CVE-2014-9277
|
2024-11-21 11:20 |
2015-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276972
|
- |
|
mediawiki
|
mediawiki
|
Cross-site request forgery (CSRF) vulnerability in the Special:ExpandedTemplates page in MediaWiki before 1.19.22, 1.20.x through 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgRawHTML is s…
|
CWE-352
Origin Validation Error
|
CVE-2014-9276
|
2024-11-21 11:20 |
2015-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276973
|
- |
|
microweber
|
microweber
|
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute arbitrary SQL commands via the category parameter when displaying a category, rel…
|
CWE-89
SQL Injection
|
CVE-2014-9464
|
2024-11-21 11:20 |
2015-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276974
|
- |
|
php
|
php
|
sapi/cgi/cgi_main.c in the CGI component in PHP through 5.4.36, 5.5.x through 5.5.20, and 5.6.x through 5.6.4, when mmap is used to read a .php file, does not properly consider the mapping's length d…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9427
|
2024-11-21 11:20 |
2015-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276975
|
- |
|
reality66
|
cart66_lite
|
Directory traversal vulnerability in models/Cart66.php in the Cart66 Lite plugin before 1.5.4 for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the member_…
|
CWE-22
Path Traversal
|
CVE-2014-9461
|
2024-11-21 11:20 |
2015-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276976
|
- |
|
linux
|
linux_kernel
|
The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of a…
|
CWE-399
Resource Management Errors
|
CVE-2014-9428
|
2024-11-21 11:20 |
2015-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276977
|
- |
|
justin_klein
|
wp-vipergb
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the WP-ViperGB plugin before 1.3.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that…
|
CWE-352
Origin Validation Error
|
CVE-2014-9460
|
2024-11-21 11:20 |
2015-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276978
|
- |
|
e107
|
e107
|
Cross-site request forgery (CSRF) vulnerability in the AdminObserver function in e107_admin/users.php in e107 2.0 alpha2 allows remote attackers to hijack the authentication of administrators for req…
|
CWE-352
Origin Validation Error
|
CVE-2014-9459
|
2024-11-21 11:20 |
2015-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276979
|
- |
|
hex-rays
|
ida
|
Heap-based buffer overflow in the GDB debugger module in Hex-Rays IDA Pro before 6.6 cumulative fix 2014-12-24 allows remote GDB servers to have unspecified impact via unknown vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9458
|
2024-11-21 11:20 |
2015-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276980
|
- |
|
pmb_services
|
pmb
|
SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the id parameter to catalog.php.
|
CWE-89
SQL Injection
|
CVE-2014-9457
|
2024-11-21 11:20 |
2015-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|