|
276681
|
- |
|
redhat
|
tcpdump
|
Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of service (crash) via a crafted length value in an OLSR f…
|
CWE-189
Numeric Errors
|
CVE-2014-8767
|
2024-11-21 11:19 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276682
|
- |
|
zte
|
zxhn_h108l_firmware
|
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8493
|
2024-11-21 11:19 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276683
|
- |
|
advantech
|
eki-6340_firmware eki-6340
|
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.
|
CWE-78
OS Command
|
CVE-2014-8387
|
2024-11-21 11:19 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276684
|
- |
|
debian xen opensuse
|
debian_linux xen opensuse
|
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a craf…
|
CWE-17
Code
|
CVE-2014-8595
|
2024-11-21 11:19 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276685
|
- |
|
opensuse debian xen
|
opensuse debian_linux xen
|
The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointe…
|
CWE-20
Improper Input Validation
|
CVE-2014-8594
|
2024-11-21 11:19 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276686
|
- |
|
pandorafms
|
pandora_flexible_monitoring_system
|
Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via the refr parameter to i…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8629
|
2024-11-21 11:19 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276687
|
- |
|
mantisbt
|
mantisbt
|
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via th…
|
CWE-19
Data Processing Errors
|
CVE-2014-8598
|
2024-11-21 11:19 |
2014-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276688
|
- |
|
freebsd
|
freebsd
|
FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attacker…
|
CWE-17
Code
|
CVE-2014-8475
|
2024-11-21 11:19 |
2014-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276689
|
- |
|
codecanyon
|
phpsound
|
Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Description fields in a playlist or the (3…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8954
|
2024-11-21 11:19 |
2014-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276690
|
- |
|
phpscriptlerim
|
php_scriptlerim_who\'s_who
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to hijack the authentication of administrators or requests that (1) add an admin …
|
CWE-352
Origin Validation Error
|
CVE-2014-8953
|
2024-11-21 11:19 |
2014-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|