|
282701
|
- |
|
cisco
|
adaptive_security_appliance
|
The Identity Firewall (IDFW) functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to trigger authentication-state modifications via a crafted NetBIOS logout probe…
|
CWE-20
Improper Input Validation
|
CVE-2014-0653
|
2024-11-21 11:02 |
2014-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282702
|
- |
|
cisco
|
context_directory_agent
|
Cross-site scripting (XSS) vulnerability in the Mappings page in Cisco Context Directory Agent (CDA) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuj…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0652
|
2024-11-21 11:02 |
2014-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282703
|
- |
|
cisco
|
context_directory_agent
|
The administrative interface in Cisco Context Directory Agent (CDA) does not properly enforce authorization requirements, which allows remote authenticated users to obtain administrative access by hi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0651
|
2024-11-21 11:02 |
2014-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282704
|
- |
|
technicolor
|
tc7200_firmware tc7200
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to hijack the authentication of administrators for requests that …
|
CWE-352
Origin Validation Error
|
CVE-2014-0621
|
2024-11-21 11:02 |
2014-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282705
|
- |
|
technicolor
|
tc7200_firmware tc7200
|
Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to inject arbitrary web script or HTML via the (1) ADDNewDomain paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0620
|
2024-11-21 11:02 |
2014-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282706
|
- |
|
freerdp
|
freerdp
|
Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a denial of service (application crash) or possibly h…
|
CWE-189
Numeric Errors
|
CVE-2014-0791
|
2024-11-21 11:02 |
2014-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282707
|
6.2 |
MEDIUM
Local
|
qemu fedoraproject redhat
|
qemu fedora enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation virtualization enterprise_lin…
|
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-0147
|
2024-11-21 11:01 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282708
|
5.5 |
MEDIUM
Local
|
qemu redhat
|
qemu enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation virtualization enterprise_linux_eus …
|
Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_s…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2014-0148
|
2024-11-21 11:01 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282709
|
8.6 |
HIGH
Local
|
qemu redhat
|
qemu enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation virtualization enterprise_linux_eus …
|
QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input va…
|
CWE-20
Improper Input Validation
|
CVE-2014-0144
|
2024-11-21 11:01 |
2022-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282710
|
9.8 |
CRITICAL
Network
|
manageiq
|
awesomespawn
|
Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, at…
|
CWE-78
OS Command
|
CVE-2014-0156
|
2024-11-21 11:01 |
2022-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|