|
277891
|
6.5 |
MEDIUM
Network
|
reviewboard
|
review_board
|
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive in…
|
CWE-200
Information Exposure
|
CVE-2014-5028
|
2024-11-21 11:11 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277892
|
4.3 |
MEDIUM
Network
|
avolvesoftware
|
projectdox
|
Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.
|
CWE-200
Information Exposure
|
CVE-2014-5132
|
2024-11-21 11:11 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277893
|
6.5 |
MEDIUM
Network
|
avolvesoftware
|
projectdox
|
Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse.
|
CWE-200
Information Exposure
|
CVE-2014-5131
|
2024-11-21 11:11 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277894
|
6.5 |
MEDIUM
Network
|
avolvesoftware
|
projectdox
|
Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via vectors involving a direct access token.
|
CWE-200
Information Exposure
|
CVE-2014-5130
|
2024-11-21 11:11 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277895
|
9.8 |
CRITICAL
Network
|
google
|
android
|
**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands via the delete method.
|
CWE-89
SQL Injection
|
CVE-2014-4959
|
2024-11-21 11:11 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277896
|
9.8 |
CRITICAL
Network
|
frog_cms_project
|
frog_cms
|
An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-4912
|
2024-11-21 11:11 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277897
|
8.8 |
HIGH
Network
|
invisioncommunity
|
invision_power_board
|
SQL injection vulnerability in Invision Power Board (aka IPB or IP.Board) before 3.4.6 allows remote attackers to execute arbitrary SQL commands via the cId parameter.
|
CWE-89
SQL Injection
|
CVE-2014-4928
|
2024-11-21 11:11 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277898
|
9.8 |
CRITICAL
Network
|
thycotic
|
secret_server
|
The Remote Desktop Launcher in Thycotic Secret Server before 8.6.000010 does not properly cleanup a temporary file that contains an encrypted password once a session has ended.
|
CWE-255
Credentials Management
|
CVE-2014-4861
|
2024-11-21 11:11 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277899
|
9.8 |
CRITICAL
Network
|
gnu
|
libgfortran
|
Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of service (Fortran application crash) via vectors related to array allocation.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-5044
|
2024-11-21 11:11 |
2018-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277900
|
8.1 |
HIGH
Network
|
docker
|
docker
|
Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.
|
CWE-20
Improper Input Validation
|
CVE-2014-5282
|
2024-11-21 11:11 |
2018-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|