|
277751
|
7.8 |
HIGH
Local
|
codders-dataset_project
|
codders-dataset
|
(1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby place credentials on the mysqldump command line, which allows local users to o…
|
CWE-200
Information Exposure
|
CVE-2014-4991
|
2024-11-21 11:11 |
2018-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277752
|
5.9 |
MEDIUM
Network
|
huawei
|
s9300_firmware s9300e_firmware s7700_firmware s9700_firmware s5700_firmware s6700_firmware s5300_firmware s6300_firmware s2300_firmware s2700_firmware s3300_firmware …
|
Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.
|
CWE-200
Information Exposure
|
CVE-2014-5394
|
2024-11-21 11:11 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277753
|
9.8 |
CRITICAL
Network
|
freenas
|
freenas
|
FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.
|
CWE-254
7PK - Security Features
|
CVE-2014-5334
|
2024-11-21 11:11 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277754
|
9.8 |
CRITICAL
Network
|
microsemi
|
s350i_firmware
|
SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execute arbitrary SQL commands via vectors involving a username.
|
CWE-89
SQL Injection
|
CVE-2014-5071
|
2024-11-21 11:11 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277755
|
6.1 |
MEDIUM
Network
|
microsemi
|
s350i_firmware
|
Cross-site scripting (XSS) vulnerability in Symmetricom s350i 2.70.15 allows remote attackers to inject arbitrary web script or HTML via vectors involving system logs.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5069
|
2024-11-21 11:11 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277756
|
9.8 |
CRITICAL
Network
|
ajax_upload_for_gravity_forms_project
|
ajax_upload_for_gravity_forms
|
Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extensi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-4972
|
2024-11-21 11:11 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277757
|
5.5 |
MEDIUM
Local
|
rawstudio fedoraproject
|
rawstudio fedora
|
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-gr…
|
CWE-59
Link Following
|
CVE-2014-4978
|
2024-11-21 11:11 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277758
|
9.8 |
CRITICAL
Network
|
zend debian
|
zend_framework debian_linux
|
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2014-4914
|
2024-11-21 11:11 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277759
|
7.2 |
HIGH
Network
|
landesk
|
landesk_management_suite
|
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1)…
|
CWE-20
Improper Input Validation
|
CVE-2014-5362
|
2024-11-21 11:11 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277760
|
8.8 |
HIGH
Network
|
manageengine
|
servicedesk_plus assetexplorer supportcenter it360
|
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to ex…
|
CWE-22
Path Traversal
|
CVE-2014-5302
|
2024-11-21 11:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|