|
280301
|
5.9 |
MEDIUM
Network
|
maradns_project deadwood_project
|
maradns deadwood
|
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2031
|
2024-11-21 11:05 |
2018-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280302
|
8.8 |
HIGH
Network
|
subscribe_to_comments_reloaded_project
|
subscribe_to_comments_reloaded
|
Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for req…
|
CWE-352
Origin Validation Error
|
CVE-2014-2274
|
2024-11-21 11:05 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280303
|
7.8 |
HIGH
Local
|
echor_project
|
echor
|
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login credentials by watching the process table.
|
CWE-255
Credentials Management
|
CVE-2014-1835
|
2024-11-21 11:05 |
2018-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280304
|
7.8 |
HIGH
Local
|
echor_project
|
echor
|
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary code by adding a semi-colon in their username or password.
|
CWE-77
Command Injection
|
CVE-2014-1834
|
2024-11-21 11:05 |
2018-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280305
|
6.1 |
MEDIUM
Network
|
oxidforge
|
eshop
|
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and …
|
CWE-93
CRLF Injection
|
CVE-2014-2017
|
2024-11-21 11:05 |
2018-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280306
|
7.1 |
HIGH
Adjacent
|
arubanetworks
|
clearpass
|
Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2071
|
2024-11-21 11:05 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280307
|
5.5 |
MEDIUM
Local
|
numpy redhat fedoraproject
|
numpy enterprise_linux fedora
|
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink at…
|
CWE-59
Link Following
|
CVE-2014-1859
|
2024-11-21 11:05 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280308
|
5.5 |
MEDIUM
Local
|
numpy
|
numpy
|
__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.
|
CWE-20
Improper Input Validation
|
CVE-2014-1858
|
2024-11-21 11:05 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280309
|
9.8 |
CRITICAL
Network
|
tapatalk
|
tapatalk
|
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API r…
|
CWE-89
SQL Injection
|
CVE-2014-2023
|
2024-11-21 11:05 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280310
|
7.1 |
HIGH
Local
|
perltidy_project
|
perltidy
|
The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpn…
|
CWE-284
Improper Access Control
|
CVE-2014-2277
|
2024-11-21 11:05 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|