|
279331
|
7.8 |
HIGH
Local
|
opensuse mdadm_project
|
opensuse mdadm
|
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
|
CWE-77
Command Injection
|
CVE-2014-5220
|
2024-11-21 11:11 |
2018-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279332
|
9.8 |
CRITICAL
Network
|
tinywebgallery
|
wordpress_flash_uploader
|
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
|
CWE-77
Command Injection
|
CVE-2014-5014
|
2024-11-21 11:11 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279333
|
8.8 |
HIGH
Network
|
wpsecurityauditlog
|
wp_security_audit_log
|
Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vect…
|
CWE-352
Origin Validation Error
|
CVE-2014-5072
|
2024-11-21 11:11 |
2018-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279334
|
8.8 |
HIGH
Network
|
fresh-media
|
brute_force_login_protection
|
Cross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests tha…
|
CWE-352
Origin Validation Error
|
CVE-2014-5034
|
2024-11-21 11:11 |
2018-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279335
|
9.8 |
CRITICAL
Network
|
drupal
|
storage_api
|
The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2013-003.
|
CWE-20
Improper Input Validation
|
CVE-2014-5170
|
2024-11-21 11:11 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279336
|
6.5 |
MEDIUM
Network
|
reviewboard
|
review_board
|
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive in…
|
CWE-200
Information Exposure
|
CVE-2014-5028
|
2024-11-21 11:11 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279337
|
4.3 |
MEDIUM
Network
|
avolvesoftware
|
projectdox
|
Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.
|
CWE-200
Information Exposure
|
CVE-2014-5132
|
2024-11-21 11:11 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279338
|
6.5 |
MEDIUM
Network
|
avolvesoftware
|
projectdox
|
Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse.
|
CWE-200
Information Exposure
|
CVE-2014-5131
|
2024-11-21 11:11 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279339
|
6.5 |
MEDIUM
Network
|
avolvesoftware
|
projectdox
|
Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via vectors involving a direct access token.
|
CWE-200
Information Exposure
|
CVE-2014-5130
|
2024-11-21 11:11 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279340
|
9.8 |
CRITICAL
Network
|
google
|
android
|
**DISPUTED** SQL injection vulnerability in SQLiteDatabase.java in the SQLi Api in Android allows remote attackers to execute arbitrary SQL commands via the delete method.
|
CWE-89
SQL Injection
|
CVE-2014-4959
|
2024-11-21 11:11 |
2018-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|