|
277951
|
- |
|
landesk
|
landesk_management_suite
|
Cross-site scripting (XSS) vulnerability in the admin interface in LANDESK Management Suite before 9.6 SP1 allows remote attackers to inject arbitrary web script or HTML via the AMTVersion parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2014-5360
|
2024-11-21 11:11 |
2015-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277952
|
- |
|
attachmate
|
reflection_ftp_client
|
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-5211
|
2024-11-21 11:11 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277953
|
- |
|
siemens
|
simatic_wincc_sm\@rtclient
|
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism.
|
CWE-200
Information Exposure
|
CVE-2014-5233
|
2024-11-21 11:11 |
2015-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277954
|
- |
|
siemens
|
simatic_wincc_sm\@rtclient
|
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-password requirement by leveraging the running of the app in the background state.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5232
|
2024-11-21 11:11 |
2015-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277955
|
- |
|
siemens
|
simatic_wincc_sm\@rtclient
|
The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the password from storage via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2014-5231
|
2024-11-21 11:11 |
2015-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277956
|
- |
|
facebook
|
hiphop_virtual_machine
|
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for rem…
|
CWE-310
Cryptographic Issues
|
CVE-2014-5386
|
2024-11-21 11:11 |
2014-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277957
|
- |
|
microfocus
|
access_manager
|
Cross-site request forgery (CSRF) vulnerability in nps/servlet/webacc in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.1 allows remote attackers to hijack the authentic…
|
CWE-352
Origin Validation Error
|
CVE-2014-5217
|
2024-11-21 11:11 |
2014-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277958
|
- |
|
microfocus
|
access_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject arbitrary web script or HTML via (1) the location parameter in …
|
CWE-79
Cross-site Scripting
|
CVE-2014-5216
|
2024-11-21 11:11 |
2014-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277959
|
- |
|
microfocus
|
access_manager
|
NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated administrators to discover service-account passwords via a request to (1) roma/jsp/volsc/monitoring/dev_services.jsp or (2)…
|
CWE-200
Information Exposure
|
CVE-2014-5215
|
2024-11-21 11:11 |
2014-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277960
|
- |
|
microfocus
|
access_manager
|
nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query pa…
|
NVD-CWE-Other
|
CVE-2014-5214
|
2024-11-21 11:11 |
2014-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|