|
279631
|
- |
|
wireshark
|
wireshark
|
The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' and '\r' characters, which allows remote atta…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-5162
|
2024-11-21 11:11 |
2014-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279632
|
- |
|
wireshark
|
wireshark
|
The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' characters, which allows remote attackers to cause a denial…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-5161
|
2024-11-21 11:11 |
2014-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279633
|
- |
|
hp
|
data_protector
|
Multiple directory traversal vulnerabilities in crs.exe in the Cell Request Service in HP Data Protector allow remote attackers to create arbitrary files via an opcode-1091 request, or create or dele…
|
CWE-22
Path Traversal
|
CVE-2014-5160
|
2024-11-21 11:11 |
2014-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279634
|
- |
|
linux suse redhat canonical
|
linux_kernel linux_enterprise_desktop linux_enterprise_server linux_enterprise_real_time_extension enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_eus ub…
|
The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dere…
|
CWE-476
NULL Pointer Dereference
|
CVE-2014-5077
|
2024-11-21 11:11 |
2014-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279635
|
- |
|
linux redhat
|
linux_kernel enterprise_linux_server_aus enterprise_linux_server_tus enterprise_linux_eus
|
The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a s…
|
CWE-59
Link Following
|
CVE-2014-5045
|
2024-11-21 11:11 |
2014-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279636
|
- |
|
sap
|
fi_manager_self-service
|
SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2014-5176
|
2024-11-21 11:11 |
2014-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279637
|
- |
|
sap
|
solution_manager
|
The License Measurement servlet in SAP Solution Manager 7.1 allows remote attackers to bypass authentication via unspecified vectors, related to a verb tampering attack and SAP_JTECHS.
|
CWE-287
Improper Authentication
|
CVE-2014-5175
|
2024-11-21 11:11 |
2014-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279638
|
- |
|
sap
|
netweaver_business_warehouse
|
The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 function group, which allows remote authenticated users to obtain sensitive info…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5174
|
2024-11-21 11:11 |
2014-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279639
|
- |
|
sap
|
hana_extended_application_services
|
SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that was once public.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5173
|
2024-11-21 11:11 |
2014-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279640
|
- |
|
sap
|
hana
|
Multiple cross-site scripting (XSS) vulnerabilities in the XS Administration Tools in SAP HANA allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5172
|
2024-11-21 11:11 |
2014-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|