|
279521
|
- |
|
plack_project
|
plack
|
Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a c…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5269
|
2024-11-21 11:11 |
2014-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279522
|
- |
|
tibco
|
spotfire_server
|
Unspecified vulnerability in the Authentication Module in TIBCO Spotfire Server before 4.5.2, 5.0.x before 5.0.3, 5.5.x before 5.5.2, 6.0.x before 6.0.3, and 6.5.x before 6.5.1 allows remote attacker…
|
NVD-CWE-noinfo
|
CVE-2014-5285
|
2024-11-21 11:11 |
2014-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279523
|
- |
|
check_mk_project
|
check_mk
|
The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object,…
|
CWE-94
Code Injection
|
CVE-2014-5340
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279524
|
- |
|
check_mk_project
|
check_mk
|
Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk files) to arbitrary locations via vectors related to row selections.
|
NVD-CWE-noinfo
|
CVE-2014-5339
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279525
|
- |
|
iii
|
sierra
|
Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate ac…
|
CWE-200
Information Exposure
|
CVE-2014-5137
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279526
|
- |
|
iii
|
sierra
|
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5136
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279527
|
- |
|
labanquepostale
|
labanquepostale
|
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banki…
|
CWE-200
Information Exposure
|
CVE-2014-5076
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279528
|
- |
|
spi-inc
|
ganeti
|
The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5247
|
2024-11-21 11:11 |
2014-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279529
|
- |
|
xen
|
xen
|
Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5147
|
2024-11-21 11:11 |
2014-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279530
|
- |
|
gnu debian
|
glibc debian_linux
|
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code …
|
CWE-189
Numeric Errors
|
CVE-2014-5119
|
2024-11-21 11:11 |
2014-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|