|
280291
|
5.5 |
MEDIUM
Local
|
x_file_explorer_project debian
|
x_file_explorer debian_linux
|
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2079
|
2024-11-21 11:05 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280292
|
7.8 |
HIGH
Local
|
enlightenment
|
enlightenment
|
Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1846
|
2024-11-21 11:05 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280293
|
7.8 |
HIGH
Local
|
enlightenment
|
enlightenment
|
An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the environment.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1845
|
2024-11-21 11:05 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280294
|
7.5 |
HIGH
Network
|
eshtery.she7ata
|
eshtery_cms
|
Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx.
|
CWE-22
Path Traversal
|
CVE-2014-2069
|
2024-11-21 11:05 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280295
|
5.3 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a fai…
|
CWE-200
Information Exposure
|
CVE-2014-2078
|
2024-11-21 11:05 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280296
|
9.8 |
CRITICAL
Network
|
3ds
|
catia
|
Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "CATV5_Backbone_Bus."
|
CWE-787
Out-of-bounds Write
|
CVE-2014-2073
|
2024-11-21 11:05 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280297
|
8.8 |
HIGH
Network
|
opendocman
|
opendocman
|
OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to them…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1946
|
2024-11-21 11:05 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280298
|
6.5 |
MEDIUM
Network
|
buddypress
|
buddypress
|
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1889
|
2024-11-21 11:05 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280299
|
9.8 |
CRITICAL
Network
|
owncloud
|
owncloud
|
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.
|
CWE-284
Improper Access Control
|
CVE-2014-2048
|
2024-11-21 11:05 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280300
|
5.9 |
MEDIUM
Network
|
maradns_project deadwood_project
|
maradns deadwood
|
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging…
|
CWE-20 CWE-125
Improper Input Validation Out-of-bounds Read
|
CVE-2014-2032
|
2024-11-21 11:05 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|