|
276461
|
6.5 |
MEDIUM
Network
|
libjpeg-turbo fedoraproject canonical
|
libjpeg-turbo fedora ubuntu_linux
|
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9092
|
2024-11-21 11:20 |
2017-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276462
|
9.8 |
CRITICAL
Network
|
mpfr
|
gnu_mpfr
|
Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have unspecified impact via vectors related to incorrect documentation for mpn_set_str.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9474
|
2024-11-21 11:20 |
2017-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276463
|
5.4 |
MEDIUM
Network
|
openkm
|
openkm
|
Cross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML via the Tasks parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8957
|
2024-11-21 11:20 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276464
|
8.8 |
HIGH
Network
|
vbseo
|
vbseo
|
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php.
|
CWE-94
Code Injection
|
CVE-2014-9463
|
2024-11-21 11:20 |
2017-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276465
|
7.5 |
HIGH
Network
|
gnu
|
emacs
|
Emacs 24.4 allows remote attackers to bypass security restrictions.
|
CWE-200
Information Exposure
|
CVE-2014-9483
|
2024-11-21 11:20 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276466
|
6.1 |
MEDIUM
Network
|
vbulletin
|
vbulletin
|
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9469
|
2024-11-21 11:20 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276467
|
8.8 |
HIGH
Network
|
10web
|
photo_gallery
|
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-9312
|
2024-11-21 11:20 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276468
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In all Qualcomm products with Android releases from CAF using the Linux kernel, the use of an out-of-range pointer offset is potentially possible in rollback protection.
|
CWE-118
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9411
|
2024-11-21 11:20 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276469
|
8.2 |
HIGH
Network
|
snapcreek
|
duplicator
|
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9262
|
2024-11-21 11:20 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276470
|
8.8 |
HIGH
Network
|
downloadmanager
|
download_manager
|
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9260
|
2024-11-21 11:20 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|