|
280481
|
6.5 |
MEDIUM
Network
|
cisco
|
ios_xe ios
|
The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attack…
|
CWE-20
Improper Input Validation
|
CVE-2014-2146
|
2024-11-21 11:05 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280482
|
- |
|
apache
|
tapestry
|
Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consum…
|
CWE-399
Resource Management Errors
|
CVE-2014-1972
|
2024-11-21 11:05 |
2015-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280483
|
- |
|
impresscms
|
impresscms
|
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_pat…
|
CWE-22
Path Traversal
|
CVE-2014-1836
|
2024-11-21 11:05 |
2015-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280484
|
- |
|
cisco
|
telepresence_tc_software telepresence_te_software
|
Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obtain root privileges by sending packets on the local…
|
CWE-284
Improper Access Control
|
CVE-2014-2174
|
2024-11-21 11:05 |
2015-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280485
|
- |
|
y-cam
|
ycb004_firmware ycb002_firmware yck002_firmware yck003_firmware yceb03_firmware ycb001_firmware ycblhd5_firmware ycblb3_firmware ycblb3 ycb003_firmware ycw003_firmware
|
Multiple cross-site scripting (XSS) vulnerabilities in Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD…
|
CWE-79
Cross-site Scripting
|
CVE-2014-1902
|
2024-11-21 11:05 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280486
|
- |
|
y-cam
|
yceb03_firmware ycb004_firmware ycb002_firmware ycbl03_firmware ycbl03 ycblb3_firmware ycblb3 yck002_firmware ycblhd5_firmware ycw003_firmware ycw001_firmware ycw002_…
|
Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and Y…
|
CWE-20
Improper Input Validation
|
CVE-2014-1901
|
2024-11-21 11:05 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280487
|
- |
|
y-cam
|
ycb002_firmware ycb004_firmware ycw003_firmware ycb001_firmware ycblhd5_firmware ycbl03_firmware ycbl03 ycblb3_firmware ycblb3 ycw001_firmware yck004_firmware yck003_…
|
Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and Y…
|
CWE-200
Information Exposure
|
CVE-2014-1900
|
2024-11-21 11:05 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280488
|
- |
|
egroupware
|
egroupware
|
eGroupware before 1.8.006.20140217 allows remote attackers to conduct PHP object injection attacks, delete arbitrary files, and possibly execute arbitrary code via the (1) addr_fields or (2) trans pa…
|
CWE-94
Code Injection
|
CVE-2014-2027
|
2024-11-21 11:05 |
2015-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280489
|
- |
|
cisco
|
secure_access_control_system
|
Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configu…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2130
|
2024-11-21 11:05 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280490
|
- |
|
phusion
|
passenger
|
Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists beca…
|
NVD-CWE-Other
|
CVE-2014-1832
|
2024-11-21 11:05 |
2015-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|