|
279771
|
- |
|
siemens
|
simatic_s7_cpu_1200_firmware simatic_s7_cpu-1211c simatic_s7_cpu_1212c simatic_s7_cpu_1214c simatic_s7_cpu_1215c simatic_s7_cpu_1217c
|
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2908
|
2024-11-21 11:07 |
2014-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279772
|
- |
|
xen
|
xen
|
Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vecto…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2915
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279773
|
- |
|
wireshark
|
wireshark
|
The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to …
|
NVD-CWE-noinfo
|
CVE-2014-2907
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279774
|
- |
|
drupal debian
|
drupal debian_linux
|
Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input informati…
|
CWE-200
Information Exposure
|
CVE-2014-2983
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279775
|
- |
|
sixnet
|
sixview_manager
|
Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 18081.
|
CWE-22
Path Traversal
|
CVE-2014-2976
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279776
|
- |
|
qemu
|
qemu
|
Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a…
|
CWE-189
Numeric Errors
|
CVE-2014-2894
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279777
|
- |
|
opensuse llvm
|
opensuse clang
|
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directo…
|
CWE-59
Link Following
|
CVE-2014-2893
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279778
|
- |
|
herry
|
sfpagent
|
lib/sfpagent/bsig.rb in the sfpagent gem before 0.4.15 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the module name in a JSON request.
|
NVD-CWE-Other
|
CVE-2014-2888
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279779
|
- |
|
samba
|
rsync
|
The check_secret function in authenticate.c in rsync 3.1.0 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a user name which does not exist in…
|
CWE-20
Improper Input Validation
|
CVE-2014-2855
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279780
|
- |
|
yassl
|
cyassl
|
wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2)…
|
CWE-20
Improper Input Validation
|
CVE-2014-2899
|
2024-11-21 11:07 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|