|
279491
|
- |
|
openssl
|
openssl
|
The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attac…
|
CWE-310
Cryptographic Issues
|
CVE-2014-3570
|
2024-11-21 11:08 |
2015-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279492
|
- |
|
zohocorp
|
manageengine_adselfservice_plus
|
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine ADSelfService Plus before 5.2 Build 5202 allows remote attackers to inject arbitrary web script or HTML via the name parameter to GroupSu…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3779
|
2024-11-21 11:08 |
2015-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279493
|
- |
|
paloaltonetworks
|
pan-os
|
Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.x before 6.0.6 allows remote attackers t…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3764
|
2024-11-21 11:08 |
2015-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279494
|
- |
|
apache
|
solr
|
Cross-site scripting (XSS) vulnerability in the Admin UI Plugin / Stats page in Apache Solr 4.x before 4.10.3 allows remote attackers to inject arbitrary web script or HTML via the fieldvaluecache ob…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3628
|
2024-11-21 11:08 |
2015-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279495
|
- |
|
f5
|
nginx
|
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-i…
|
CWE-77
Command Injection
|
CVE-2014-3556
|
2024-11-21 11:08 |
2014-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279496
|
- |
|
openssl
|
openssl
|
The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, and 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attackers to cause a denia…
|
NVD-CWE-Other
|
CVE-2014-3569
|
2024-11-21 11:08 |
2014-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279497
|
- |
|
cisco
|
adaptive_security_appliance_software
|
The syslog-management subsystem in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain an administrator password by waiting for an administrator to copy a file, and the…
|
CWE-200
Information Exposure
|
CVE-2014-3410
|
2024-11-21 11:08 |
2014-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279498
|
- |
|
redhat apache debian apple
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server_eus enterprise_linux_server enterprise_linux_hpc_node subversion debian_linux xcode
|
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server cra…
|
NVD-CWE-Other
|
CVE-2014-3580
|
2024-11-21 11:08 |
2014-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279499
|
- |
|
apple apache canonical
|
mac_os_x os_x_server http_server ubuntu_linux
|
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3583
|
2024-11-21 11:08 |
2014-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279500
|
- |
|
vmware
|
vcenter_server_appliance
|
Cross-site scripting (XSS) vulnerability in VMware vCenter Server Appliance (vCSA) 5.1 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3797
|
2024-11-21 11:08 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|