|
279541
|
- |
|
openstack opensuse
|
horizon opensuse
|
Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrator…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3475
|
2024-11-21 11:08 |
2014-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279542
|
- |
|
openstack opensuse
|
horizon opensuse
|
Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Ju…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3474
|
2024-11-21 11:08 |
2014-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279543
|
- |
|
openstack opensuse
|
horizon opensuse
|
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in the Horizon Orchestration dashboard in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno b…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3473
|
2024-11-21 11:08 |
2014-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279544
|
- |
|
openstack redhat
|
nova openstack
|
OpenStack Compute (Nova) before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (CPU consumption) via an IP filter in a list active servers API re…
|
CWE-399
Resource Management Errors
|
CVE-2014-3708
|
2024-11-21 11:08 |
2014-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279545
|
- |
|
adaptivecomputing
|
torque_resource_manager
|
The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the pro…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3684
|
2024-11-21 11:08 |
2014-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279546
|
- |
|
apache
|
wss4j cxf
|
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation …
|
CWE-287
Improper Authentication
|
CVE-2014-3623
|
2024-11-21 11:08 |
2014-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279547
|
- |
|
apache
|
cxf
|
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the au…
|
CWE-399
Resource Management Errors
|
CVE-2014-3584
|
2024-11-21 11:08 |
2014-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279548
|
- |
|
bss
|
continuity_cms
|
SQL injection vulnerability in wcm/system/pages/admin/getnode.aspx in BSS Continuity CMS 4.2.22640.0 allows remote attackers to execute arbitrary SQL commands via the nodeid parameter.
|
CWE-89
SQL Injection
|
CVE-2014-3446
|
2024-11-21 11:08 |
2014-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279549
|
- |
|
pidgin
|
pidgin
|
The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sensitive information from process memory via a craft…
|
CWE-200
Information Exposure
|
CVE-2014-3698
|
2024-11-21 11:08 |
2014-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279550
|
- |
|
pidgin
|
pidgin
|
Absolute path traversal vulnerability in the untar_block function in win32/untar.c in Pidgin before 2.10.10 on Windows allows remote attackers to write to arbitrary files via a drive name in a tar ar…
|
CWE-22
Path Traversal
|
CVE-2014-3697
|
2024-11-21 11:08 |
2014-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|