|
283501
|
- |
|
websense
|
triton_web_security_gateway_anywhere triton_web_security triton_unified_security_center triton_web_filter triton_web_security_gateway
|
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix…
|
CWE-255
Credentials Management
|
CVE-2014-0347
|
2024-11-21 11:01 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283502
|
- |
|
elfutils_project
|
elfutils
|
Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (ap…
|
CWE-189
Numeric Errors
|
CVE-2014-0172
|
2024-11-21 11:01 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283503
|
- |
|
fortinet
|
fortiadc_firmware fortiadc-1000e fortiadc-1500d fortiadc-2000d fortiadc-200d fortiadc-300e fortiadc-4000d fortiadc-400e fortiadc-600e
|
Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the locale param…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0331
|
2024-11-21 11:01 |
2014-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283504
|
- |
|
wordpress
|
wordpress
|
The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it e…
|
CWE-287
Improper Authentication
|
CVE-2014-0166
|
2024-11-21 11:01 |
2014-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283505
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role, related to wp-admin/includes/post.php and wp-admin/includes/class-…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0165
|
2024-11-21 11:01 |
2014-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283506
|
- |
|
microsoft
|
windows_xp windows_server_2008 windows_server_2012 windows_rt windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8 windows_server_2003
|
Untrusted search path vulnerability in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows…
|
CWE-426
Untrusted Search Path
|
CVE-2014-0315
|
2024-11-21 11:01 |
2014-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283507
|
- |
|
huawei
|
echo_life_hg8247_firmware echo_life
|
Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2014-0337
|
2024-11-21 11:01 |
2014-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283508
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be gr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0093
|
2024-11-21 11:01 |
2014-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283509
|
- |
|
oracle apache
|
retail_applications tomcat commons_fileupload
|
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU co…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0050
|
2024-11-21 11:01 |
2014-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283510
|
- |
|
redhat
|
richfaces jboss_web_framework_kit
|
The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a…
|
CWE-20
Improper Input Validation
|
CVE-2014-0086
|
2024-11-21 11:01 |
2014-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|