|
281281
|
- |
|
yealink
|
voip_phone_firmware
|
CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model paramete…
|
NVD-CWE-Other
|
CVE-2014-3427
|
2024-11-21 11:08 |
2014-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281282
|
- |
|
infoblox
|
netmri
|
Infoblox NetMRI before 6.8.5 has a default password of admin for the "root" MySQL database account, which makes it easier for local users to obtain access via unspecified vectors.
|
CWE-255
Credentials Management
|
CVE-2014-3419
|
2024-11-21 11:08 |
2014-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281283
|
- |
|
infoblox
|
netmri
|
config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter.
|
CWE-78
OS Command
|
CVE-2014-3418
|
2024-11-21 11:08 |
2014-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281284
|
- |
|
juniper
|
junos srx100 srx110 srx1400 srx210 srx220 srx240 srx3400 srx3600 srx550 srx5600 srx5800 srx650
|
Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 before 12.1X46-D10, and 12.1X47 before 12.1X47-D10 on SRX Series devices, allows …
|
CWE-20
Improper Input Validation
|
CVE-2014-3822
|
2024-11-21 11:08 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281285
|
- |
|
juniper
|
junos
|
Cross-site scripting (XSS) vulnerability in SRX Web Authentication (webauth) in Juniper Junos 11.4 before 11.4R11, 12.1X44 before 12.1X44-D34, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, …
|
CWE-79
Cross-site Scripting
|
CVE-2014-3821
|
2024-11-21 11:08 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281286
|
- |
|
juniper
|
junos
|
Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R10, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R8, 12.3 before…
|
CWE-20
Improper Input Validation
|
CVE-2014-3819
|
2024-11-21 11:08 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281287
|
- |
|
juniper
|
junos srx100 srx110 srx1400 srx210 srx220 srx240 srx3400 srx3600 srx550 srx5600 srx5800 srx650
|
Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translat…
|
CWE-20
Improper Input Validation
|
CVE-2014-3817
|
2024-11-21 11:08 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281288
|
- |
|
juniper
|
junos
|
Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R11, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R8-S2, 12.3 bef…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3816
|
2024-11-21 11:08 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281289
|
- |
|
juniper
|
junos srx100 srx110 srx1400 srx210 srx220 srx240 srx3400 srx3600 srx550 srx5600 srx5800 srx650
|
Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to cause a denial of service (flowd crash) via a crafted SIP packet.
|
CWE-20
Improper Input Validation
|
CVE-2014-3815
|
2024-11-21 11:08 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281290
|
- |
|
apache
|
syncope
|
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.
|
CWE-310
Cryptographic Issues
|
CVE-2014-3503
|
2024-11-21 11:08 |
2014-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|