|
276881
|
8.8 |
HIGH
Network
|
openmicroscopy
|
omero
|
OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.
|
CWE-352
Origin Validation Error
|
CVE-2014-7198
|
2024-11-21 11:16 |
2019-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276882
|
7.8 |
HIGH
Local
|
sddm_project fedoraproject
|
sddm fedora
|
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may h…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7272
|
2024-11-21 11:16 |
2018-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276883
|
7.8 |
HIGH
Local
|
sddm_project fedoraproject
|
sddm fedora
|
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2014-7271
|
2024-11-21 11:16 |
2018-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276884
|
6.5 |
MEDIUM
Network
|
teamspeak
|
teamspeak3
|
Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connecting to a channel with a different client instance, …
|
CWE-20
Improper Input Validation
|
CVE-2014-7222
|
2024-11-21 11:16 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276885
|
6.5 |
MEDIUM
Network
|
teamspeak
|
teamspeak3
|
TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a different client instance,…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-7221
|
2024-11-21 11:16 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276886
|
5.9 |
MEDIUM
Network
|
ms-ins
|
sumaho sumaho_driving_capability_diagnosis
|
The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to s…
|
CWE-295
Improper Certificate Validation
|
CVE-2014-7242
|
2024-11-21 11:16 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276887
|
6.1 |
MEDIUM
Network
|
formget
|
easy_contact_form_solution
|
Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value parameter in a …
|
CWE-79
Cross-site Scripting
|
CVE-2014-7240
|
2024-11-21 11:16 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276888
|
9.8 |
CRITICAL
Network
|
kankunit
|
konke_smart_plug_firmware
|
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7279
|
2024-11-21 11:16 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276889
|
6.1 |
MEDIUM
Network
|
nex-forms_lite_project
|
nex-forms_lite
|
Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms Lite plugin 2.1.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the form_fields parameter in a (…
|
CWE-79
Cross-site Scripting
|
CVE-2014-7151
|
2024-11-21 11:16 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276890
|
- |
|
yahoo
|
messenger
|
Multiple stack-based buffer overflows in Yahoo! Messenger 11.5.0.228 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the (1) shortcut o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-7216
|
2024-11-21 11:16 |
2015-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|