|
277491
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_server
|
Synacor Zimbra Collaboration before 8.0.8 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5500
|
2024-11-21 11:12 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277492
|
6.5 |
MEDIUM
Network
|
konakart
|
konakart
|
Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for req…
|
CWE-352
Origin Validation Error
|
CVE-2014-5516
|
2024-11-21 11:12 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277493
|
7.8 |
HIGH
Local
|
sniffit_project debian
|
sniffit debian_linux
|
Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and addres…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-5439
|
2024-11-21 11:12 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277494
|
7.5 |
HIGH
Network
|
honeywell
|
experion_process_knowledge_system
|
A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to possible information d…
|
CWE-22
Path Traversal
|
CVE-2014-5436
|
2024-11-21 11:12 |
2019-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277495
|
9.8 |
CRITICAL
Network
|
honeywell
|
experion_process_knowledge_system
|
An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remot…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-5435
|
2024-11-21 11:12 |
2019-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277496
|
9.8 |
CRITICAL
Network
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700…
|
CWE-255
Credentials Management
|
CVE-2014-5433
|
2024-11-21 11:12 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277497
|
9.8 |
CRITICAL
Network
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A remote attacker may …
|
CWE-287
Improper Authentication
|
CVE-2014-5432
|
2024-11-21 11:12 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277498
|
6.8 |
MEDIUM
Physics
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, which provides access to basic biomedical information…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2014-5431
|
2024-11-21 11:12 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277499
|
9.8 |
CRITICAL
Network
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FTP protocol. Baxter …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2014-5434
|
2024-11-21 11:12 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277500
|
5.5 |
MEDIUM
Local
|
zarafa
|
zarafa_collaboration_platform
|
Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive information by reading license files.
|
CWE-200
Information Exposure
|
CVE-2014-5450
|
2024-11-21 11:12 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|