|
279671
|
- |
|
x
|
xf86-video-intel
|
Directory traversal vulnerability in tools/backlight_helper.c in X.Org xf86-video-intel 2.99.911 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the interface nam…
|
CWE-22
Path Traversal
|
CVE-2014-4910
|
2024-11-21 11:11 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279672
|
- |
|
tenable
|
nessus web_ui
|
The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.
|
CWE-200
Information Exposure
|
CVE-2014-4980
|
2024-11-21 11:11 |
2014-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279673
|
- |
|
citrix
|
xenserver
|
Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive information by modifying the guest virtual hard disk (V…
|
NVD-CWE-noinfo
|
CVE-2014-4948
|
2024-11-21 11:11 |
2014-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279674
|
- |
|
citrix
|
xenserver
|
Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4947
|
2024-11-21 11:11 |
2014-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279675
|
- |
|
gitlist
|
gitlist
|
Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkou…
|
NVD-CWE-Other
|
CVE-2014-5023
|
2024-11-21 11:11 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279676
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled t…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5022
|
2024-11-21 11:11 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279677
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5021
|
2024-11-21 11:11 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279678
|
- |
|
drupal
|
drupal
|
The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5020
|
2024-11-21 11:11 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279679
|
- |
|
drupal
|
drupal
|
The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration fil…
|
CWE-20
Improper Input Validation
|
CVE-2014-5019
|
2024-11-21 11:11 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279680
|
- |
|
polarssl debian
|
polarssl debian_linux
|
The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersu…
|
CWE-310
Cryptographic Issues
|
CVE-2014-4911
|
2024-11-21 11:11 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|