|
280511
|
- |
|
sap
|
netweaver
|
The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4003
|
2024-11-21 11:09 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280512
|
- |
|
ibm
|
vios aix
|
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix…
|
CWE-59
Link Following
|
CVE-2014-3977
|
2024-11-21 11:09 |
2014-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280513
|
- |
|
cisofy
|
lynis
|
include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.*.unsorted file with an easily determined name.
|
CWE-59
Link Following
|
CVE-2014-3986
|
2024-11-21 11:09 |
2014-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280514
|
- |
|
cisofy
|
lynis
|
include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.##### file.
|
CWE-59
Link Following
|
CVE-2014-3982
|
2024-11-21 11:09 |
2014-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280515
|
- |
|
php
|
php
|
acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.
|
CWE-59
Link Following
|
CVE-2014-3981
|
2024-11-21 11:09 |
2014-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280516
|
- |
|
libav
|
libav
|
Multiple unspecified vulnerabilities in Libav before 0.8.12 allow remote attackers to have unknown impact and vectors.
|
NVD-CWE-noinfo
|
CVE-2014-3984
|
2024-11-21 11:09 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280517
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in Special:PasswordReset in MediaWiki before 1.19.16, 1.21.x before 1.21.10, and 1.22.x before 1.22.7, when wgRawHtml is enabled, allows remote attackers to i…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3966
|
2024-11-21 11:09 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280518
|
- |
|
xen
|
xen
|
Xen 4.4.x, when running on an ARM system, does not properly check write permissions on virtual addresses, which allows local guest administrators to gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3969
|
2024-11-21 11:09 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280519
|
- |
|
xen opensuse
|
xen opensuse
|
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a large number of crafted requests, which trigger an e…
|
NVD-CWE-noinfo
|
CVE-2014-3968
|
2024-11-21 11:09 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280520
|
- |
|
xen opensuse
|
xen opensuse
|
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of servic…
|
NVD-CWE-Other
|
CVE-2014-3967
|
2024-11-21 11:09 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|