|
277691
|
7.5 |
HIGH
Network
|
open-xchange
|
open-xchange_appsuite
|
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files vi…
|
CWE-22
Path Traversal
|
CVE-2014-5236
|
2024-11-21 11:11 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277692
|
9.6 |
CRITICAL
Network
|
eucalyptus
|
eucalyptus_management_console
|
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5039
|
2024-11-21 11:11 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277693
|
6.8 |
MEDIUM
Physics
|
tianocore
|
edk2
|
Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended acce…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-4860
|
2024-11-21 11:11 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277694
|
6.8 |
MEDIUM
Physics
|
tianocore
|
edk2
|
Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restri…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-4859
|
2024-11-21 11:11 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277695
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central manageengine_desktop_central_managed_service_providers
|
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows rem…
|
CWE-22
Path Traversal
|
CVE-2014-5007
|
2024-11-21 11:11 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277696
|
7.8 |
HIGH
Local
|
open-xchange
|
open-xchange_appsuite
|
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified imp…
|
CWE-611
XXE
|
CVE-2014-5238
|
2024-11-21 11:11 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277697
|
7.5 |
HIGH
Network
|
iii
|
sierra
|
Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instances of the same parameter, which allows remote attackers to bypass parameter va…
|
NVD-CWE-Other
|
CVE-2014-5138
|
2024-11-21 11:11 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277698
|
9.8 |
CRITICAL
Network
|
granding
|
grand_ma300_firmware
|
Grand MA 300 allows a brute-force attack on the PIN.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2014-5381
|
2024-11-21 11:11 |
2020-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277699
|
7.5 |
HIGH
Network
|
granding
|
grand_ma300_firmware
|
Grand MA 300 allows retrieval of the access PIN from sniffed data.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2014-5380
|
2024-11-21 11:11 |
2020-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277700
|
9.8 |
CRITICAL
Network
|
status2k
|
status2k
|
Status2k does not remove the install directory allowing credential reset.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2014-5093
|
2024-11-21 11:11 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|