|
277881
|
- |
|
jig
|
jigbrowser\+
|
The jigbrowser+ application 1.8.1 and earlier for iOS allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5318
|
2024-11-21 11:11 |
2014-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277882
|
- |
|
adobe
|
coldfusion acrobat
|
Cross-site scripting (XSS) vulnerability in the Help page in Adobe Acrobat 9.5.2 and earlier and ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspec…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5315
|
2024-11-21 11:11 |
2014-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277883
|
- |
|
yukoyuko
|
_yuko_yuko
|
The Yuko Yuko (aka jp.co.yukoyuko.android.yukoyuko_android) application 1.0.5 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to …
|
CWE-310
Cryptographic Issues
|
CVE-2014-5323
|
2024-11-21 11:11 |
2014-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277884
|
- |
|
sos
|
jobscheduler
|
XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a requ…
|
NVD-CWE-Other
|
CVE-2014-5392
|
2024-11-21 11:11 |
2014-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277885
|
- |
|
eset
|
smart_security endpoint_security
|
The ESET Personal Firewall NDIS filter (EpFwNdis.sys) driver in the Firewall Module Build 1183 (20140214) and earlier in ESET Smart Security and ESET Endpoint Security products 5.0 through 7.0 allows…
|
CWE-20
Improper Input Validation
|
CVE-2014-4973
|
2024-11-21 11:11 |
2014-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277886
|
- |
|
filemaker
|
filemaker_pro filemaker_pro_advanced
|
Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 13 and Pro Advanced before 13 allows remote attackers to inject arbitrary web script or HTML via u…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5322
|
2024-11-21 11:11 |
2014-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277887
|
- |
|
filemaker
|
filemaker_pro filemaker_pro_advanced
|
FileMaker Pro before 13 and Pro Advanced before 13 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via …
|
CWE-310
Cryptographic Issues
|
CVE-2014-5321
|
2024-11-21 11:11 |
2014-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277888
|
- |
|
bump_project
|
bump
|
The Bump application for Android does not properly handle implicit intents, which allows attackers to obtain sensitive owner-name information via a crafted application.
|
CWE-200
Information Exposure
|
CVE-2014-5320
|
2024-11-21 11:11 |
2014-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277889
|
- |
|
dotclear
|
dotclear
|
Cross-site scripting (XSS) vulnerability in Dotclear before 2.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted page.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5316
|
2024-11-21 11:11 |
2014-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277890
|
- |
|
schneider-electric aveva
|
scada_expert_clearscada clearscada
|
Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script …
|
CWE-79
Cross-site Scripting
|
CVE-2014-5411
|
2024-11-21 11:11 |
2014-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|