|
282781
|
- |
|
vmware
|
vcloud_director
|
Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.
|
CWE-352
Origin Validation Error
|
CVE-2014-1211
|
2024-11-21 11:03 |
2014-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282782
|
- |
|
vmware
|
esxi workstation fusion player esx
|
VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of …
|
NVD-CWE-Other
|
CVE-2014-1208
|
2024-11-21 11:03 |
2014-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282783
|
- |
|
vmware
|
esxi esx
|
VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Network File Copy (NFC) traffic.
|
NVD-CWE-Other
|
CVE-2014-1207
|
2024-11-21 11:03 |
2014-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282784
|
- |
|
openwebanalytics
|
open_web_analytics
|
SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the owa_email_address parameter in a base…
|
CWE-89
SQL Injection
|
CVE-2014-1206
|
2024-11-21 11:03 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282785
|
- |
|
lorex_technology lorextechnology
|
edge_lh310_firmware edge edge3_lh340_firmware edge3 edge2_lh330_firmware edge2 edge\+_lh320_firmware edge\+
|
Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-1201
|
2024-11-21 11:03 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282786
|
- |
|
graphviz
|
graphviz
|
Stack-based buffer overflow in the yyerror function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via a long line in a dot file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0978
|
2024-11-21 11:03 |
2014-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282787
|
- |
|
sixapart
|
movabletype
|
Cross-site scripting (XSS) vulnerability in the Rich Text Editor in Movable Type 5.0x, 5.1x before 5.161, 5.2.x before 5.2.9, and 6.0.x before 6.0.1 allows remote attackers to inject arbitrary web sc…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0977
|
2024-11-21 11:03 |
2014-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282788
|
- |
|
graphviz
|
graphviz
|
Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via vectors related to a "badly formed number" and a "lon…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-1236
|
2024-11-21 11:03 |
2014-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282789
|
- |
|
paratrooper-newrelic_project
|
paratrooper-newrelic
|
The paratrooper-newrelic gem 1.0.1 for Ruby allows local users to obtain the X-Api-Key value by listing the curl process.
|
CWE-200
Information Exposure
|
CVE-2014-1234
|
2024-11-21 11:03 |
2014-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282790
|
- |
|
tobias_maier
|
paratrooper-pingdom
|
The paratrooper-pingdom gem 1.0.0 for Ruby allows local users to obtain the App-Key, username, and password values by listing the curl process.
|
CWE-200
Information Exposure
|
CVE-2014-1233
|
2024-11-21 11:03 |
2014-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|