|
278291
|
7.5 |
HIGH
Network
|
huawei
|
s9300_firmware s9700_firmware s7700_firmware s5300_firmware s5700_firmware s6300_firmware s6700_firmware ar150_firmware ar160_firmware ar200_firmware ar1200_firmware …
|
Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, A…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4705
|
2024-11-21 11:10 |
2018-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278292
|
5.9 |
MEDIUM
Network
|
python simplejson_project opensuse_project opensuse
|
python simplejson opensuse
|
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negati…
|
CWE-129
Improper Validation of Array Index
|
CVE-2014-4616
|
2024-11-21 11:10 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278293
|
5.3 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information a…
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2014-4843
|
2024-11-21 11:10 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278294
|
8.8 |
HIGH
Adjacent
|
huawei
|
campus_s7700_firmware campus_s9300_firmware campus_s9700_firmware
|
Huawei Campus S7700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9300 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9700 with software V200R001C00…
|
CWE-284
Improper Access Control
|
CVE-2014-4707
|
2024-11-21 11:10 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278295
|
7.5 |
HIGH
Network
|
huawei
|
campus_s3700hi_firmware s5700_firmware s6700_firmware s3300hi_firmware s5300_firmware s6300_firmware s9300_firmware s7700_firmware lsw_s9700_firmware campus_s5700_firmware<…
|
Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Campus S7700 with software V200R003C00SPC300,V200R003C00SPC500; LSW S9700 with software V200R001C0…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4706
|
2024-11-21 11:10 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278296
|
7.8 |
HIGH
Local
|
gpgtools
|
libmacgpg
|
The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary commands with root privileges via shell metacharacters…
|
CWE-77
Command Injection
|
CVE-2014-4677
|
2024-11-21 11:10 |
2017-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278297
|
- |
|
ibm
|
uefi
|
IBM Unified Extensible Firmware Interface (UEFI) on Flex System x880 X6, System x3850 X6, and System x3950 X6 devices allows remote authenticated users to cause an unspecified temporary denial of ser…
|
NVD-CWE-noinfo
|
CVE-2014-4768
|
2024-11-21 11:10 |
2015-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278298
|
- |
|
ibm
|
endpoint_manager_family license_metric_tool
|
IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which a…
|
CWE-20
Improper Input Validation
|
CVE-2014-4778
|
2024-11-21 11:10 |
2015-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278299
|
- |
|
ibm
|
endpoint_manager_family license_metric_tool
|
Cross-site request forgery (CSRF) vulnerability in the login page in IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 allows remote attackers t…
|
CWE-352
Origin Validation Error
|
CVE-2014-4774
|
2024-11-21 11:10 |
2015-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278300
|
- |
|
ibm
|
license_metric_tool
|
IBM License Metric Tool 9 before 9.1.0.2 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain access by leveraging an unattended…
|
CWE-200
Information Exposure
|
CVE-2014-4776
|
2024-11-21 11:10 |
2015-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|