|
276811
|
- |
|
cisco
|
unified_communications_manager
|
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which …
|
CWE-310
Cryptographic Issues
|
CVE-2014-7991
|
2024-11-21 11:18 |
2014-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276812
|
- |
|
hp
|
helion_cloud_development_platform
|
The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers…
|
CWE-310
Cryptographic Issues
|
CVE-2014-7878
|
2024-11-21 11:18 |
2014-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276813
|
- |
|
huawei
|
mobile_partner_firmware ec156 ec176 ec177
|
Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.d…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8359
|
2024-11-21 11:18 |
2014-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276814
|
- |
|
redhat
|
libvirt
|
The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML…
|
CWE-255
Credentials Management
|
CVE-2014-7823
|
2024-11-21 11:18 |
2014-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276815
|
7.8 |
HIGH
Local
|
linux opensuse suse
|
linux_kernel evergreen suse_linux_enterprise_server
|
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or ca…
|
CWE-476
NULL Pointer Dereference
|
CVE-2014-7826
|
2024-11-21 11:18 |
2014-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276816
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of servi…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-7825
|
2024-11-21 11:18 |
2014-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276817
|
7.8 |
HIGH
Local
|
linux debian opensuse suse
|
linux_kernel debian_linux evergreen linux_enterprise_real_time_extension suse_linux_enterprise_server
|
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to caus…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-8369
|
2024-11-21 11:18 |
2014-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276818
|
- |
|
sprockets_project
|
sprockets
|
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.…
|
CWE-22
Path Traversal
|
CVE-2014-7819
|
2024-11-21 11:18 |
2014-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276819
|
- |
|
rubyonrails opensuse
|
ruby_on_rails rails opensuse
|
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4…
|
CWE-22
Path Traversal
|
CVE-2014-7818
|
2024-11-21 11:18 |
2014-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276820
|
- |
|
cisco
|
ios_xe air-ct5760 ws-c3850 ws-c3860
|
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access…
|
CWE-20
Improper Input Validation
|
CVE-2014-7990
|
2024-11-21 11:18 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|