|
279321
|
8.8 |
HIGH
Network
|
kemptechnologies
|
loadmaster
|
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).
|
CWE-74
Injection
|
CVE-2014-5287
|
2024-11-21 11:11 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279322
|
5.3 |
MEDIUM
Network
|
ntp f5
|
ntp big-ip_local_traffic_manager big-ip_wan_optimization_manager big-ip_edge_gateway big-ip_analytics big-ip_access_policy_manager big-ip_global_traffic_manager big-iq_centralize…
|
An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2014-5209
|
2024-11-21 11:11 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279323
|
8.8 |
HIGH
Network
|
loadedcommerce
|
loaded7
|
The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct S…
|
CWE-89
SQL Injection
|
CVE-2014-5140
|
2024-11-21 11:11 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279324
|
9.8 |
CRITICAL
Network
|
senkas_kolibri_project
|
senkas_kolibri
|
Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request.
|
CWE-20
Improper Input Validation
|
CVE-2014-5289
|
2024-11-21 11:11 |
2019-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279325
|
6.1 |
MEDIUM
Network
|
zend debian
|
zend_framework debian_linux
|
ZF2014-03 has a potential cross site scripting vector in multiple view helpers
|
CWE-79
Cross-site Scripting
|
CVE-2014-4913
|
2024-11-21 11:11 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279326
|
7.0 |
HIGH
Local
|
xcfa_project debian
|
xcfa debian_linux
|
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files. Note: A different vulnerability than CVE-2014-5254.
|
CWE-362
Race Condition
|
CVE-2014-5255
|
2024-11-21 11:11 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279327
|
4.7 |
MEDIUM
Local
|
xcfa_project
|
xcfa
|
xcfa before 5.0.1 creates temporary files insecurely which could allow local users to launch a symlink attack and overwrite arbitrary files.
|
CWE-362
Race Condition
|
CVE-2014-5254
|
2024-11-21 11:11 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279328
|
5.5 |
MEDIUM
Local
|
trusted_boot_project redhat fedoraproject
|
trusted_boot enterprise_linux fedora
|
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
|
CWE-20
Improper Input Validation
|
CVE-2014-5118
|
2024-11-21 11:11 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279329
|
9.8 |
CRITICAL
Network
|
hospira
|
mednet
|
Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the targ…
|
CWE-94
Code Injection
|
CVE-2014-5401
|
2024-11-21 11:11 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279330
|
6.1 |
MEDIUM
Network
|
wordfence
|
wordfence_security
|
Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4932
|
2024-11-21 11:11 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|