|
276811
|
- |
|
drupal
|
doubleclick_for_publishers
|
Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8748
|
2024-11-21 11:19 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276812
|
- |
|
drupal
|
commons
|
Cross-site scripting (XSS) vulnerability in the Drupal Commons module 7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to content c…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8747
|
2024-11-21 11:19 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276813
|
- |
|
drupal
|
skeleton_theme
|
Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8746
|
2024-11-21 11:19 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276814
|
- |
|
drupal
|
custom_search_module
|
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" pe…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8745
|
2024-11-21 11:19 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276815
|
- |
|
drupal
|
nivo_slider
|
Cross-site scripting (XSS) vulnerability in the Nivo Slider module 7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users with the "administer nivo slider" permission to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8744
|
2024-11-21 11:19 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276816
|
- |
|
drupal
|
maestro
|
Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8743
|
2024-11-21 11:19 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276817
|
9.1 |
CRITICAL
Network
|
redhat
|
cloudforms_management_engine
|
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.
|
CWE-295
Improper Certificate Validation
|
CVE-2014-8164
|
2024-11-21 11:18 |
2022-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276818
|
8.1 |
HIGH
Network
|
google
|
android
|
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via …
|
CWE-863
Incorrect Authorization
|
CVE-2014-7914
|
2024-11-21 11:18 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276819
|
4.6 |
MEDIUM
Physics
|
google
|
android
|
Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitr…
|
CWE-22
Path Traversal
|
CVE-2014-7951
|
2024-11-21 11:18 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276820
|
9.8 |
CRITICAL
Network
|
zend redhat fedoraproject
|
zend_framework enterprise_linux fedora
|
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands…
|
CWE-89
SQL Injection
|
CVE-2014-8089
|
2024-11-21 11:18 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|