|
277551
|
7.5 |
HIGH
Network
|
twistedmatrix
|
twisted
|
Python Twisted 14.0 trustRoot is not respected in HTTP client
|
CWE-295
Improper Certificate Validation
|
CVE-2014-7143
|
2024-11-21 11:16 |
2019-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277552
|
8.8 |
HIGH
Network
|
openmicroscopy
|
omero
|
OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.
|
CWE-352
Origin Validation Error
|
CVE-2014-7198
|
2024-11-21 11:16 |
2019-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277553
|
7.8 |
HIGH
Local
|
sddm_project fedoraproject
|
sddm fedora
|
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may h…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7272
|
2024-11-21 11:16 |
2018-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277554
|
7.8 |
HIGH
Local
|
sddm_project fedoraproject
|
sddm fedora
|
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2014-7271
|
2024-11-21 11:16 |
2018-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277555
|
6.5 |
MEDIUM
Network
|
teamspeak
|
teamspeak3
|
Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connecting to a channel with a different client instance, …
|
CWE-20
Improper Input Validation
|
CVE-2014-7222
|
2024-11-21 11:16 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277556
|
6.5 |
MEDIUM
Network
|
teamspeak
|
teamspeak3
|
TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a different client instance,…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-7221
|
2024-11-21 11:16 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277557
|
5.9 |
MEDIUM
Network
|
ms-ins
|
sumaho sumaho_driving_capability_diagnosis
|
The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to s…
|
CWE-295
Improper Certificate Validation
|
CVE-2014-7242
|
2024-11-21 11:16 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277558
|
6.1 |
MEDIUM
Network
|
formget
|
easy_contact_form_solution
|
Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value parameter in a …
|
CWE-79
Cross-site Scripting
|
CVE-2014-7240
|
2024-11-21 11:16 |
2017-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277559
|
9.8 |
CRITICAL
Network
|
kankunit
|
konke_smart_plug_firmware
|
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7279
|
2024-11-21 11:16 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277560
|
6.1 |
MEDIUM
Network
|
nex-forms_lite_project
|
nex-forms_lite
|
Multiple cross-site scripting (XSS) vulnerabilities in the NEX-Forms Lite plugin 2.1.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the form_fields parameter in a (…
|
CWE-79
Cross-site Scripting
|
CVE-2014-7151
|
2024-11-21 11:16 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|