|
279691
|
- |
|
google
|
chrome
|
extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote attackers to spoof the extension permission dialog b…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3170
|
2024-11-21 11:07 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279692
|
- |
|
opensuse debian google
|
opensuse debian_linux chrome
|
Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or po…
|
NVD-CWE-Other
|
CVE-2014-3169
|
2024-11-21 11:07 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279693
|
- |
|
google opensuse debian
|
chrome opensuse debian_linux
|
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other …
|
NVD-CWE-Other
|
CVE-2014-3168
|
2024-11-21 11:07 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279694
|
- |
|
ibm
|
emptoris_spend_analysis
|
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authe…
|
CWE-352
Origin Validation Error
|
CVE-2014-3061
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279695
|
- |
|
ibm
|
emptoris_contract_management
|
SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows re…
|
CWE-89
SQL Injection
|
CVE-2014-3041
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279696
|
- |
|
ibm
|
emptoris_spend_analysis
|
Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3035
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279697
|
- |
|
ibm
|
emptoris_contract_management
|
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFi…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3034
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279698
|
- |
|
cisco
|
ios_xr asr_9000_rsp440_router asr_9001 asr_9006 asr_9010 asr_9904 asr_9912 asr_9922
|
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of…
|
CWE-20
Improper Input Validation
|
CVE-2014-3335
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279699
|
- |
|
ibm
|
emptoris_spend_analysis emptoris_sourcing_portfolio emptoris_contract_management
|
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.…
|
CWE-352
Origin Validation Error
|
CVE-2014-3040
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279700
|
- |
|
ibm
|
emptoris_sourcing_portfolio
|
Cross-site scripting (XSS) vulnerability in IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authen…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3033
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|