|
280481
|
- |
|
zyxel
|
p-660hw
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change …
|
CWE-352
Origin Validation Error
|
CVE-2014-4162
|
2024-11-21 11:09 |
2014-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280482
|
- |
|
reviewboard
|
djblets
|
Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3995
|
2024-11-21 11:09 |
2014-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280483
|
- |
|
reviewboard
|
djblets reviewboard
|
Cross-site scripting (XSS) vulnerability in util/templatetags/djblets_js.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django, as used in Review Board, allows remote attackers to inject arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3994
|
2024-11-21 11:09 |
2014-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280484
|
- |
|
sap
|
supplier_relationship_management
|
Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to inject arbitrary web script or HTML via the url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4161
|
2024-11-21 11:09 |
2014-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280485
|
- |
|
sap
|
netweaver_business_client
|
Multiple cross-site scripting (XSS) vulnerabilities in the testcanvas node in SAP NetWeaver Business Client (NWBC) allow remote attackers to inject arbitrary web script or HTML via the (1) title or (…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4160
|
2024-11-21 11:09 |
2014-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280486
|
- |
|
sap
|
supplier_relationship_management
|
Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a …
|
NVD-CWE-Other
|
CVE-2014-4159
|
2024-11-21 11:09 |
2014-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280487
|
- |
|
senkas
|
kolibri
|
Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4158
|
2024-11-21 11:09 |
2014-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280488
|
- |
|
isc
|
bind
|
libdns in ISC BIND 9.10.0 before P2 does not properly handle EDNS options, which allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted packet,…
|
CWE-20
Improper Input Validation
|
CVE-2014-3859
|
2024-11-21 11:09 |
2014-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280489
|
- |
|
ckeditor
|
fckeditor
|
Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4037
|
2024-11-21 11:09 |
2014-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280490
|
- |
|
impresscms
|
impresscms
|
Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a listimg action.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4036
|
2024-11-21 11:09 |
2014-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|