|
278931
|
- |
|
dhcpcd_project google
|
dhcpcd android
|
The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) serve…
|
CWE-399
Resource Management Errors
|
CVE-2014-6060
|
2024-11-21 11:13 |
2014-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278932
|
- |
|
mcafee
|
web_gateway
|
The Accounts tab in the administrative user interface in McAfee Web Gateway (MWG) before 7.3.2.9 and 7.4.x before 7.4.2 allows remote authenticated users to obtain the hashed user passwords via unspe…
|
CWE-200
Information Exposure
|
CVE-2014-6064
|
2024-11-21 11:13 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278933
|
- |
|
google
|
android_browser
|
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-6041
|
2024-11-21 11:13 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278934
|
- |
|
-
|
-
|
Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.
|
-
|
CVE-2014-5470
|
2024-11-21 11:12 |
2024-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278935
|
8.8 |
HIGH
Network
|
getrailo
|
railo
|
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obta…
|
CWE-20
Improper Input Validation
|
CVE-2014-5468
|
2024-11-21 11:12 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278936
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_server
|
Synacor Zimbra Collaboration before 8.0.8 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5500
|
2024-11-21 11:12 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278937
|
6.5 |
MEDIUM
Network
|
konakart
|
konakart
|
Cross-site request forgery (CSRF) vulnerability in the Storefront Application in DS Data Systems KonaKart before 7.3.0.0 allows remote attackers to hijack the authentication of administrators for req…
|
CWE-352
Origin Validation Error
|
CVE-2014-5516
|
2024-11-21 11:12 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278938
|
7.8 |
HIGH
Local
|
sniffit_project debian
|
sniffit debian_linux
|
Multiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass Non-eXecutable bit NX, stack smashing protector SSP, and addres…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-5439
|
2024-11-21 11:12 |
2019-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278939
|
7.5 |
HIGH
Network
|
honeywell
|
experion_process_knowledge_system
|
A directory traversal vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to possible information d…
|
CWE-22
Path Traversal
|
CVE-2014-5436
|
2024-11-21 11:12 |
2019-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278940
|
9.8 |
CRITICAL
Network
|
honeywell
|
experion_process_knowledge_system
|
An arbitrary memory write vulnerability exists in the dual_onsrv.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, that could lead to possible remot…
|
CWE-787
Out-of-bounds Write
|
CVE-2014-5435
|
2024-11-21 11:12 |
2019-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|