|
277501
|
7.8 |
HIGH
Local
|
seafile
|
seafile_server
|
Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling user accounts.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5443
|
2024-11-21 11:12 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277502
|
5.5 |
MEDIUM
Local
|
clipboard_project
|
clipboard
|
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.
|
CWE-59
Link Following
|
CVE-2014-5509
|
2024-11-21 11:12 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277503
|
9.1 |
CRITICAL
Network
|
beckhoff
|
embedded_pc_images twincat
|
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remote Configuration To…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5415
|
2024-11-21 11:12 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277504
|
9.1 |
CRITICAL
Network
|
beckhoff
|
embedded_pc_images twincat
|
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it easier for remote atta…
|
CWE-254
7PK - Security Features
|
CVE-2014-5414
|
2024-11-21 11:12 |
2016-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277505
|
- |
|
johnsoncontrols
|
metsys
|
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka…
|
NVD-CWE-Other
|
CVE-2014-5428
|
2024-11-21 11:12 |
2015-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277506
|
- |
|
johnsoncontrols
|
metsys
|
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (…
|
CWE-200
Information Exposure
|
CVE-2014-5427
|
2024-11-21 11:12 |
2015-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277507
|
- |
|
ge
|
multilink_ml3100_firmware multilink_ml3100 multilink_ml3000_firmware multilink_ml3000 multilink_ml810_firmware multilink_ml810 multilink_ml1600_firmware multilink_ml1600 multi…
|
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key a…
|
CWE-310
Cryptographic Issues
|
CVE-2014-5419
|
2024-11-21 11:12 |
2015-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277508
|
- |
|
ge
|
multilink_ml810_firmware multilink_ml810 multilink_ml1600_firmware multilink_ml1600 multilink_ml1200_firmware multilink_ml1200 multilink_ml3000_firmware multilink_ml3000 multi…
|
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to caus…
|
CWE-399
Resource Management Errors
|
CVE-2014-5418
|
2024-11-21 11:12 |
2015-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277509
|
- |
|
arris
|
touchstone_tg862g\/ct_firmware
|
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2014-5438
|
2024-11-21 11:12 |
2014-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277510
|
- |
|
arris
|
touchstone_tg862g\/ct_firmware
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of …
|
CWE-352
Origin Validation Error
|
CVE-2014-5437
|
2024-11-21 11:12 |
2014-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|