|
282761
|
- |
|
igniterealtime
|
smack
|
The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses vi…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2014-0364
|
2024-11-21 11:01 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282762
|
- |
|
igniterealtime
|
smack
|
The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows…
|
CWE-295
Improper Certificate Validation
|
CVE-2014-0363
|
2024-11-21 11:01 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282763
|
- |
|
apache
|
commons_beanutils struts
|
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the …
|
CWE-20
Improper Input Validation
|
CVE-2014-0114
|
2024-11-21 11:01 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282764
|
- |
|
f5
|
nginx
|
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0088
|
2024-11-21 11:01 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282765
|
- |
|
apache
|
struts
|
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" th…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0113
|
2024-11-21 11:01 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282766
|
- |
|
apache
|
struts
|
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0112
|
2024-11-21 11:01 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282767
|
- |
|
openstack canonical opensuse
|
neutron ubuntu_linux opensuse
|
The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a s…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0187
|
2024-11-21 11:01 |
2014-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282768
|
- |
|
zarafa
|
zarafa
|
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a denial of service (cra…
|
CWE-20
Improper Input Validation
|
CVE-2014-0079
|
2024-11-21 11:01 |
2014-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282769
|
- |
|
zarafa
|
zarafa
|
The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointe…
|
CWE-20
Improper Input Validation
|
CVE-2014-0037
|
2024-11-21 11:01 |
2014-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282770
|
- |
|
openstack
|
image_registry_and_delivery_service_\(glance\) icehouse
|
The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote authenticated users with permission to insert or m…
|
CWE-20
Improper Input Validation
|
CVE-2014-0162
|
2024-11-21 11:01 |
2014-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|