|
276871
|
5.3 |
MEDIUM
Network
|
farsite
|
farlinx_x25_gateway_firmware
|
FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature.
|
CWE-22
Path Traversal
|
CVE-2014-7174
|
2024-11-21 11:16 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276872
|
9.8 |
CRITICAL
Network
|
farsite
|
farlinx_x25_gateway_firmware
|
FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.php, iframeupload.php, or sysRestoreX25Cplt.php.
|
CWE-78
OS Command
|
CVE-2014-7173
|
2024-11-21 11:16 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276873
|
9.1 |
CRITICAL
Network
|
twiki
|
twiki
|
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.
|
CWE-74
Injection
|
CVE-2014-7236
|
2024-11-21 11:16 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276874
|
8.8 |
HIGH
Network
|
google
|
android
|
A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicio…
|
CWE-20
Improper Input Validation
|
CVE-2014-7224
|
2024-11-21 11:16 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276875
|
7.8 |
HIGH
Local
|
hp
|
sgi_tempo
|
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading et…
|
CWE-276
Incorrect Default Permissions
|
CVE-2014-7303
|
2024-11-21 11:16 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276876
|
7.8 |
HIGH
Local
|
hp
|
sgi_tempo
|
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.
|
CWE-276
Incorrect Default Permissions
|
CVE-2014-7302
|
2024-11-21 11:16 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276877
|
6.6 |
MEDIUM
Local
|
hp
|
sgi_tempo
|
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /e…
|
CWE-276
Incorrect Default Permissions
|
CVE-2014-7301
|
2024-11-21 11:16 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276878
|
6.1 |
MEDIUM
Network
|
formget
|
contact_form_integrated_with_google_maps
|
The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS
|
CWE-79
Cross-site Scripting
|
CVE-2014-7238
|
2024-11-21 11:16 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276879
|
9.8 |
CRITICAL
Network
|
dbd\
|
\
|
SQL injection vulnerability in DBD::PgPP 0.05 and earlier
|
CWE-89
SQL Injection
|
CVE-2014-7257
|
2024-11-21 11:16 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276880
|
7.5 |
HIGH
Network
|
twistedmatrix
|
twisted
|
Python Twisted 14.0 trustRoot is not respected in HTTP client
|
CWE-295
Improper Certificate Validation
|
CVE-2014-7143
|
2024-11-21 11:16 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|