|
276381
|
8.8 |
HIGH
Network
|
ibm
|
tivoli_netview_access_services
|
IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9768
|
2024-11-21 11:21 |
2016-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276382
|
9.8 |
CRITICAL
Network
|
atlassian
|
bamboo
|
The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execute arbitrary Java code via serialized data in an X…
|
CWE-20
Improper Input Validation
|
CVE-2014-9757
|
2024-11-21 11:21 |
2016-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276383
|
- |
|
libsndfile_project canonical opensuse
|
libsndfile ubuntu_linux leap opensuse
|
The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.
|
CWE-369
Divide By Zero
|
CVE-2014-9756
|
2024-11-21 11:21 |
2015-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276384
|
- |
|
atutor
|
atutor
|
Unrestricted file upload vulnerability in mods/_core/properties/lib/course.inc.php in ATutor before 2.2 patch 6 allows remote authenticated users to execute arbitrary PHP code by uploading a file wit…
|
NVD-CWE-Other
|
CVE-2014-9752
|
2024-11-21 11:21 |
2015-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276385
|
- |
|
squid-cache opensuse
|
squid opensuse
|
Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerabilit…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9749
|
2024-11-21 11:21 |
2015-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276386
|
- |
|
ntp redhat debian oracle
|
ntp enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux linux
|
The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP address is an IPv6 loopback address, which makes it ea…
|
CWE-20
Improper Input Validation
|
CVE-2014-9751
|
2024-11-21 11:21 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276387
|
- |
|
ntp redhat debian oracle
|
ntp enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation debian_linux linux
|
ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from process memory or cause a denial of service (daemo…
|
CWE-20
Improper Input Validation
|
CVE-2014-9750
|
2024-11-21 11:21 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276388
|
- |
|
freetype debian canonical opensuse
|
freetype debian_linux ubuntu_linux opensuse
|
The parse_encoding function in type1/t1load.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (infinite loop) via a "broken number-with-base" in a Postscript stream, as …
|
CWE-399
Resource Management Errors
|
CVE-2014-9745
|
2024-11-21 11:21 |
2015-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276389
|
- |
|
netsweeper
|
netsweeper
|
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and create a system backup tarball, restart the server, or stop the…
|
CWE-287
Improper Authentication
|
CVE-2014-9605
|
2024-11-21 11:21 |
2015-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276390
|
- |
|
linux
|
linux_kernel
|
The UDF filesystem implementation in the Linux kernel before 3.18.2 does not ensure that space is available for storing a symlink target's name along with a trailing \0 character, which allows local …
|
CWE-17
Code
|
CVE-2014-9731
|
2024-11-21 11:21 |
2015-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|