|
276621
|
- |
|
microfocus
|
access_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter to roma/j…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9412
|
2024-11-21 11:20 |
2014-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276622
|
- |
|
piwigo
|
piwigo
|
SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitr…
|
CWE-89
SQL Injection
|
CVE-2014-9115
|
2024-11-21 11:20 |
2014-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276623
|
- |
|
modx
|
modx_revolution
|
Cross-site scripting (XSS) vulnerability in manager/assets/fileapi/FileAPI.flash.image.swf in MODX Revolution 2.3.2-pl allows remote attackers to inject arbitrary web script or HTML via the callback …
|
CWE-79
Cross-site Scripting
|
CVE-2014-8992
|
2024-11-21 11:20 |
2014-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276624
|
- |
|
ntp
|
ntp
|
The receive function in ntp_proto.c in ntpd in NTP before 4.2.8 continues to execute after detecting a certain authentication error, which might allow remote attackers to trigger an unintended associ…
|
CWE-17
Code
|
CVE-2014-9296
|
2024-11-21 11:20 |
2014-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276625
|
- |
|
ntp
|
ntp
|
Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9295
|
2024-11-21 11:20 |
2014-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276626
|
- |
|
ntp
|
ntp
|
util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.
|
NVD-CWE-Other
|
CVE-2014-9294
|
2024-11-21 11:20 |
2014-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276627
|
- |
|
ntp
|
ntp
|
The config_auth function in ntpd in NTP before 4.2.7p11, when an auth key is not configured, improperly generates a key, which makes it easier for remote attackers to defeat cryptographic protection …
|
NVD-CWE-Other
|
CVE-2014-9293
|
2024-11-21 11:20 |
2014-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276628
|
- |
|
innominate
|
mguard_firmware
|
Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9193
|
2024-11-21 11:20 |
2014-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276629
|
- |
|
ekahau
|
activator real-time_location_system_controller b4_staff_badge_tag_firmware b4_staff_badge_tag
|
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 uses part of the MAC address as part of the RC4 setup key, which makes it …
|
CWE-200
Information Exposure
|
CVE-2014-9408
|
2024-11-21 11:20 |
2014-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276630
|
- |
|
revive-adserver
|
revive_adserver
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Revive Adserver before 3.0.5 allow remote attackers to hijack the authentication of administrators for requests that (1) delete data via …
|
CWE-352
Origin Validation Error
|
CVE-2014-9407
|
2024-11-21 11:20 |
2014-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|