|
277211
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8 windows_server_2003
|
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows …
|
CWE-129
Improper Validation of Array Index
|
CVE-2014-6317
|
2024-11-21 11:14 |
2014-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277212
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_8.1 windows_8 windows_vista windows_rt_8.1 windows_7
|
The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, an…
|
CWE-287
Improper Authentication
|
CVE-2014-6318
|
2024-11-21 11:14 |
2014-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277213
|
- |
|
opensuse phpmyadmin
|
opensuse phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arb…
|
CWE-79
Cross-site Scripting
|
CVE-2014-6300
|
2024-11-21 11:14 |
2014-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277214
|
- |
|
arubanetworks
|
clearpass
|
Cross-site request forgery (CSRF) vulnerability in the Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to hijack the authentication of a logged …
|
CWE-79
Cross-site Scripting
|
CVE-2014-6623
|
2024-11-21 11:14 |
2014-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277215
|
- |
|
arubanetworks
|
clearpass
|
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-6620
|
2024-11-21 11:14 |
2014-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277216
|
- |
|
exponentcms
|
exponent_cms
|
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the src parameter in the search action to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2014-6635
|
2024-11-21 11:14 |
2014-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277217
|
- |
|
blackberry
|
blackberry_world blackberry_os
|
The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/u…
|
CWE-20
Improper Input Validation
|
CVE-2014-6611
|
2024-11-21 11:14 |
2014-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277218
|
- |
|
cpuminer_project
|
cpuminer
|
Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a mining.subscribe response with a large nonce2 length, then triggering the overf…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-6251
|
2024-11-21 11:14 |
2014-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277219
|
- |
|
mantisbt
|
mantisbt
|
gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.
|
CWE-287
Improper Authentication
|
CVE-2014-6387
|
2024-11-21 11:14 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277220
|
- |
|
osclass
|
osclass
|
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render action to oc-admin/index.php.
|
CWE-22
Path Traversal
|
CVE-2014-6308
|
2024-11-21 11:14 |
2014-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|