|
281021
|
- |
|
doorgets
|
doorgets_cms
|
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_down_id parameter. NO…
|
CWE-89
SQL Injection
|
CVE-2014-1459
|
2024-11-21 11:04 |
2014-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281022
|
- |
|
auracms
|
auracms
|
Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLI…
|
CWE-89
SQL Injection
|
CVE-2014-1401
|
2024-11-21 11:04 |
2014-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281023
|
- |
|
siemens
|
simatic_wincc_open_architecture
|
Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-service outage) via malformed HTTP requests to port 4999.
|
CWE-399
Resource Management Errors
|
CVE-2014-1699
|
2024-11-21 11:04 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281024
|
- |
|
siemens
|
simatic_wincc_open_architecture
|
Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read arbitrary files via crafted packets to TCP port 4999.
|
CWE-22
Path Traversal
|
CVE-2014-1698
|
2024-11-21 11:04 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281025
|
- |
|
siemens
|
simatic_wincc_open_architecture
|
The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitrary code via crafted packets to TCP port 4999.
|
NVD-CWE-noinfo
|
CVE-2014-1697
|
2024-11-21 11:04 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281026
|
- |
|
siemens
|
simatic_wincc_open_architecture
|
Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for remote attackers to obtain access via a brute-force attack.
|
CWE-310
Cryptographic Issues
|
CVE-2014-1696
|
2024-11-21 11:04 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281027
|
- |
|
symantec
|
encryption_management_server
|
The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allows remote authenticated users to read the stored outbound e-mail messages of ar…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1643
|
2024-11-21 11:04 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281028
|
- |
|
citrix
|
xenmobile_device_manager xenmobile_device_manager_mdm
|
Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, and MDM 8.0.1 allows remote attackers to obtain sensitive information via unkno…
|
NVD-CWE-noinfo
|
CVE-2014-1663
|
2024-11-21 11:04 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281029
|
- |
|
mozilla oracle fedoraproject suse opensuse debian canonical
|
network_security_services seamonkey firefox firefox_esr thunderbird enterprise_manager_ops_center vm_server fedora linux_enterprise_desktop linux_enterprise_server opens…
|
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does n…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2014-1491
|
2024-11-21 11:04 |
2014-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281030
|
- |
|
mozilla oracle fedoraproject suse opensuse debian canonical
|
network_security_services seamonkey firefox firefox_esr thunderbird enterprise_manager_ops_center vm_server fedora linux_enterprise_desktop linux_enterprise_server opens…
|
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24…
|
CWE-362
Race Condition
|
CVE-2014-1490
|
2024-11-21 11:04 |
2014-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|