|
277541
|
9.8 |
CRITICAL
Network
|
farsite
|
farlinx_x25_gateway_firmware
|
FarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.
|
CWE-787
Out-of-bounds Write
|
CVE-2014-7175
|
2024-11-21 11:16 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277542
|
5.3 |
MEDIUM
Network
|
farsite
|
farlinx_x25_gateway_firmware
|
FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature.
|
CWE-22
Path Traversal
|
CVE-2014-7174
|
2024-11-21 11:16 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277543
|
9.8 |
CRITICAL
Network
|
farsite
|
farlinx_x25_gateway_firmware
|
FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php, syseditdate.php, iframeupload.php, or sysRestoreX25Cplt.php.
|
CWE-78
OS Command
|
CVE-2014-7173
|
2024-11-21 11:16 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277544
|
9.1 |
CRITICAL
Network
|
twiki
|
twiki
|
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.
|
CWE-74
Injection
|
CVE-2014-7236
|
2024-11-21 11:16 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277545
|
8.8 |
HIGH
Network
|
google
|
android
|
A Code Execution vulnerability exists in Android prior to 4.4.0 related to the addJavascriptInterface method and the accessibility and accessibilityTraversal objects, which could let a remote malicio…
|
CWE-20
Improper Input Validation
|
CVE-2014-7224
|
2024-11-21 11:16 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277546
|
7.8 |
HIGH
Local
|
hp
|
sgi_tempo
|
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading et…
|
CWE-276
Incorrect Default Permissions
|
CVE-2014-7303
|
2024-11-21 11:16 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277547
|
7.8 |
HIGH
Local
|
hp
|
sgi_tempo
|
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.
|
CWE-276
Incorrect Default Permissions
|
CVE-2014-7302
|
2024-11-21 11:16 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277548
|
6.6 |
MEDIUM
Local
|
hp
|
sgi_tempo
|
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /e…
|
CWE-276
Incorrect Default Permissions
|
CVE-2014-7301
|
2024-11-21 11:16 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277549
|
6.1 |
MEDIUM
Network
|
formget
|
contact_form_integrated_with_google_maps
|
The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS
|
CWE-79
Cross-site Scripting
|
CVE-2014-7238
|
2024-11-21 11:16 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277550
|
9.8 |
CRITICAL
Network
|
dbd\
|
\
|
SQL injection vulnerability in DBD::PgPP 0.05 and earlier
|
CWE-89
SQL Injection
|
CVE-2014-7257
|
2024-11-21 11:16 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|