|
278391
|
- |
|
apple
|
iphone_os
|
iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafte…
|
CWE-310
Cryptographic Issues
|
CVE-2014-4449
|
2024-11-21 11:10 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278392
|
- |
|
apple
|
iphone_os
|
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents direc…
|
CWE-310
Cryptographic Issues
|
CVE-2014-4448
|
2024-11-21 11:10 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278393
|
- |
|
websupporter
|
wp_amasin_-_the_amazon_affiliate_shop
|
Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pat…
|
CWE-22
Path Traversal
|
CVE-2014-4577
|
2024-11-21 11:10 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278394
|
- |
|
cbi_referral_manager_project
|
cbi_referral_manager
|
Cross-site scripting (XSS) vulnerability in getNetworkSites.php in the CBI Referral Manager plugin 1.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via t…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4517
|
2024-11-21 11:10 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278395
|
- |
|
alipay_project
|
alipay
|
Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4514
|
2024-11-21 11:10 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278396
|
- |
|
ibm
|
tririga_application_platform
|
IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote attackers to execute arbitrary code via a crafted URL.
|
CWE-20
Improper Input Validation
|
CVE-2014-4840
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278397
|
- |
|
ibm
|
tririga_application_platform
|
Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4838
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278398
|
- |
|
ibm
|
tririga_application_platform
|
Cross-site scripting (XSS) vulnerability in NewDocument.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows r…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4837
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278399
|
- |
|
ibm
|
tririga_application_platform
|
Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 all…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4836
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278400
|
- |
|
ibm
|
qradar_security_information_and_event_manager
|
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invalid input.
|
CWE-20
Improper Input Validation
|
CVE-2014-4833
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|