|
281091
|
- |
|
apple
|
iphone_os mac_os_x tvos
|
Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation a…
|
CWE-287
Improper Authentication
|
CVE-2014-1295
|
2024-11-21 11:04 |
2014-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281092
|
- |
|
carbonblack
|
carbon_black
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative …
|
CWE-352
Origin Validation Error
|
CVE-2014-1615
|
2024-11-21 11:04 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281093
|
- |
|
mozilla fedoraproject
|
bugzilla fedora
|
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authent…
|
CWE-287
Improper Authentication
|
CVE-2014-1517
|
2024-11-21 11:04 |
2014-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281094
|
- |
|
freebsd
|
freebsd
|
The NFS server (nfsserver) in FreeBSD 8.3 through 10.0 does not acquire locks in the proper order when converting a directory file handle to a vnode, which allows remote authenticated users to cause …
|
CWE-399
Resource Management Errors
|
CVE-2014-1453
|
2024-11-21 11:04 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281095
|
- |
|
pearson
|
esis_enterprise_student_information_system
|
SQL injection vulnerability in the password reset functionality in Pearson eSIS Enterprise Student Information System, possibly 3.3.0.13 and earlier, allows remote attackers to execute arbitrary SQL …
|
CWE-89
SQL Injection
|
CVE-2014-1455
|
2024-11-21 11:04 |
2014-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281096
|
- |
|
google
|
chrome
|
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.22, as used in Google Chrome before 34.0.1847.116, allow attackers to cause a denial of service or possibly have other impact via unkn…
|
NVD-CWE-noinfo
|
CVE-2014-1729
|
2024-11-21 11:04 |
2014-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281097
|
- |
|
google
|
chrome
|
Multiple unspecified vulnerabilities in Google Chrome before 34.0.1847.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2014-1728
|
2024-11-21 11:04 |
2014-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281098
|
- |
|
google
|
chrome
|
Use-after-free vulnerability in content/renderer/renderer_webcolorchooser_impl.h in Google Chrome before 34.0.1847.116 allows remote attackers to cause a denial of service or possibly have unspecifie…
|
CWE-399
Resource Management Errors
|
CVE-2014-1727
|
2024-11-21 11:04 |
2014-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281099
|
- |
|
google
|
chrome
|
The drag implementation in Google Chrome before 34.0.1847.116 allows user-assisted remote attackers to bypass the Same Origin Policy and forge local pathnames by leveraging renderer access.
|
NVD-CWE-Other
|
CVE-2014-1726
|
2024-11-21 11:04 |
2014-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281100
|
- |
|
google
|
chrome
|
The base64DecodeInternal function in wtf/text/Base64.cpp in Blink, as used in Google Chrome before 34.0.1847.116, does not properly handle string data composed exclusively of whitespace characters, w…
|
CWE-20
Improper Input Validation
|
CVE-2014-1725
|
2024-11-21 11:04 |
2014-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|