|
279611
|
- |
|
cisco
|
ios_xr asr_9000_rsp440_router asr_9001 asr_9006 asr_9010 asr_9904 asr_9912 asr_9922
|
Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3396
|
2024-11-21 11:08 |
2014-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279612
|
- |
|
openstack canonical redhat
|
keystone ubuntu_linux openstack
|
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpo…
|
CWE-200
Information Exposure
|
CVE-2014-3621
|
2024-11-21 11:08 |
2014-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279613
|
- |
|
cisco
|
webex_meetings_server
|
Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343.
|
CWE-20
Improper Input Validation
|
CVE-2014-3395
|
2024-11-21 11:08 |
2014-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279614
|
- |
|
redhat
|
hibernate_validator
|
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3558
|
2024-11-21 11:08 |
2014-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279615
|
- |
|
juniper
|
junos_pulse_secure_access_service
|
Cross-site scripting (XSS) vulnerability in the web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r6, 7.4 before 7.4r13, and 7.1 before 7.1r20 al…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3824
|
2024-11-21 11:08 |
2014-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279616
|
- |
|
juniper
|
junos_pulse_secure_access_service
|
The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r1, 7.4 before 7.4r5, and 7.1 before 7.1r18 allows remote attackers to conduct clickjacking attacks via unspe…
|
CWE-20
Improper Input Validation
|
CVE-2014-3823
|
2024-11-21 11:08 |
2014-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279617
|
- |
|
juniper
|
junos_pulse_access_control_service junos_pulse_secure_access_service
|
Cross-site scripting (XSS) vulnerability in the SSL VPN/UAC web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 7.1 before 7.1r16, 7.4 before 7.4r3, and 8.0 befo…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3820
|
2024-11-21 11:08 |
2014-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279618
|
- |
|
juniper
|
juniper_installer_service_client junos_pulse_client
|
Juniper Installer Service (JIS) Client 7.x before 7.4R6 for Windows and Junos Pulse Client before 4.0R6 allows local users to gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3811
|
2024-11-21 11:08 |
2014-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279619
|
- |
|
linux
|
linux_kernel
|
include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectly uses macros for netdev_printk and its related logging implementation, which allows remote attackers to cause a denial of servic…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3535
|
2024-11-21 11:08 |
2014-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279620
|
- |
|
linux
|
linux_kernel
|
The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to …
|
NVD-CWE-Other
|
CVE-2014-3631
|
2024-11-21 11:08 |
2014-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|