|
279721
|
- |
|
email\
|
\
|
Email::Address module before 1.904 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via vectors related to "backtracking i…
|
NVD-CWE-Other
|
CVE-2014-4720
|
2024-11-21 11:10 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279722
|
- |
|
yiiframework
|
yiiframework
|
The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.
|
CWE-94
Code Injection
|
CVE-2014-4672
|
2024-11-21 11:10 |
2014-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279723
|
- |
|
usvn
|
user-friendly_svn
|
Cross-site scripting (XSS) vulnerability in the login panel (svn/login/) in User-Friendly SVN (aka USVN) before 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the username f…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4719
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279724
|
- |
|
lunarcms
|
lunar_cms
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administrators for requests that (1) add Super users via a …
|
CWE-352
Origin Validation Error
|
CVE-2014-4718
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279725
|
- |
|
sharethis
|
simple_share_buttons_adder
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for …
|
CWE-352
Origin Validation Error
|
CVE-2014-4717
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279726
|
- |
|
thomson
|
twg87ouir
|
Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authentication of unspecified victims for requests that change passwords via the Password an…
|
CWE-352
Origin Validation Error
|
CVE-2014-4716
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279727
|
- |
|
yann_collet
|
lz4
|
Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to caus…
|
CWE-189
Numeric Errors
|
CVE-2014-4715
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279728
|
- |
|
linux suse canonical debian
|
linux_kernel linux_enterprise_desktop linux_enterprise_server linux_enterprise_real_time_extension ubuntu_linux debian_linux
|
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of servi…
|
NVD-CWE-noinfo
|
CVE-2014-4667
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279729
|
- |
|
linux suse canonical redhat
|
linux_kernel linux_enterprise_server ubuntu_linux enterprise_linux_server_aus enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_eus
|
Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-4656
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279730
|
- |
|
linux suse canonical
|
linux_kernel linux_enterprise_server ubuntu_linux
|
The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local user…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-4655
|
2024-11-21 11:10 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|