|
279901
|
- |
|
caldera
|
caldera
|
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/jobs.php or (2) costview2/printers.php.
|
CWE-89
SQL Injection
|
CVE-2014-2934
|
2024-11-21 11:07 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279902
|
- |
|
caldera
|
caldera
|
Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote attackers to access arbitrary directories via a crafted pathname.
|
CWE-22
Path Traversal
|
CVE-2014-2933
|
2024-11-21 11:07 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279903
|
- |
|
xen
|
xen
|
The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3124
|
2024-11-21 11:07 |
2014-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279904
|
- |
|
opensuse nagios
|
opensuse remote_plugin_executor
|
Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to…
|
NVD-CWE-Other
|
CVE-2014-2913
|
2024-11-21 11:07 |
2014-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279905
|
- |
|
debian strongswan
|
strongswan
|
strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.
|
NVD-CWE-Other
|
CVE-2014-2891
|
2024-11-21 11:07 |
2014-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279906
|
- |
|
ayatana_project canonical
|
unity ubuntu_linux
|
Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3204
|
2024-11-21 11:07 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279907
|
- |
|
ayatana_project canonical
|
unity ubuntu_linux
|
Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is active, which allows physically proximate attackers to bypass the lock screen and ex…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3203
|
2024-11-21 11:07 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279908
|
- |
|
ayatana_project
|
unity
|
Unity before 7.2.1 does not properly handle entry activation, which allows physically proximate attackers to bypass the lock screen by holding the ENTER key, which triggers the process to crash.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3202
|
2024-11-21 11:07 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279909
|
- |
|
f5
|
big-iq
|
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/auth…
|
CWE-255
Credentials Management
|
CVE-2014-3220
|
2024-11-21 11:07 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279910
|
- |
|
phplist
|
phplist
|
Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers to hijack the authentication of administrators via a reques…
|
CWE-352
Origin Validation Error
|
CVE-2014-2916
|
2024-11-21 11:07 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|