|
278121
|
6.5 |
MEDIUM
Network
|
piwigo
|
piwigo
|
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that add users v…
|
CWE-352
Origin Validation Error
|
CVE-2014-4613
|
2024-11-21 11:10 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278122
|
6.1 |
MEDIUM
Network
|
coppermine-gallery
|
coppermine_photo_gallery
|
Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 allows remote attackers to inject arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4612
|
2024-11-21 11:10 |
2018-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278123
|
7.5 |
HIGH
Network
|
huawei
|
s9300_firmware s9700_firmware s7700_firmware s5300_firmware s5700_firmware s6300_firmware s6700_firmware ar150_firmware ar160_firmware ar200_firmware ar1200_firmware …
|
Multiple heap-based buffer overflows in the eSap software platform in Huawei Campus S9300, S7700, S9700, S5300, S5700, S6300, and S6700 series switches; AR150, AR160, AR200, AR1200, AR2200, AR3200, A…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4705
|
2024-11-21 11:10 |
2018-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278124
|
5.9 |
MEDIUM
Network
|
python simplejson_project opensuse_project opensuse
|
python simplejson opensuse
|
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negati…
|
CWE-129
Improper Validation of Array Index
|
CVE-2014-4616
|
2024-11-21 11:10 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278125
|
5.3 |
MEDIUM
Network
|
ibm
|
curam_social_program_management
|
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information a…
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2014-4843
|
2024-11-21 11:10 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278126
|
8.8 |
HIGH
Adjacent
|
huawei
|
campus_s7700_firmware campus_s9300_firmware campus_s9700_firmware
|
Huawei Campus S7700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9300 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9700 with software V200R001C00…
|
CWE-284
Improper Access Control
|
CVE-2014-4707
|
2024-11-21 11:10 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278127
|
7.5 |
HIGH
Network
|
huawei
|
campus_s3700hi_firmware s5700_firmware s6700_firmware s3300hi_firmware s5300_firmware s6300_firmware s9300_firmware s7700_firmware lsw_s9700_firmware campus_s5700_firmware<…
|
Huawei Campus S3700HI with software V200R001C00SPC300; Campus S5700 with software V200R002C00SPC100; Campus S7700 with software V200R003C00SPC300,V200R003C00SPC500; LSW S9700 with software V200R001C0…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4706
|
2024-11-21 11:10 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278128
|
7.8 |
HIGH
Local
|
gpgtools
|
libmacgpg
|
The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary commands with root privileges via shell metacharacters…
|
CWE-77
Command Injection
|
CVE-2014-4677
|
2024-11-21 11:10 |
2017-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278129
|
- |
|
ibm
|
uefi
|
IBM Unified Extensible Firmware Interface (UEFI) on Flex System x880 X6, System x3850 X6, and System x3950 X6 devices allows remote authenticated users to cause an unspecified temporary denial of ser…
|
NVD-CWE-noinfo
|
CVE-2014-4768
|
2024-11-21 11:10 |
2015-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278130
|
- |
|
ibm
|
endpoint_manager_family license_metric_tool
|
IBM License Metric Tool 9 before 9.1.0.2 and Endpoint Manager for Software Use Analysis 9 before 9.1.0.2 do not send an X-Frame-Options HTTP header in response to requests for the login page, which a…
|
CWE-20
Improper Input Validation
|
CVE-2014-4778
|
2024-11-21 11:10 |
2015-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|