|
280571
|
7.0 |
HIGH
Local
|
fishshell
|
fish
|
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.
|
CWE-362
Race Condition
|
CVE-2014-3856
|
2024-11-21 11:08 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280572
|
9.8 |
CRITICAL
Network
|
handsomeweb
|
sos_webpages
|
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the admini…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2014-3445
|
2024-11-21 11:08 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280573
|
5.5 |
MEDIUM
Local
|
1password
|
1password
|
AgileBits 1Password through 1.0.9.340 allows security feature bypass
|
CWE-200
Information Exposure
|
CVE-2014-3753
|
2024-11-21 11:08 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280574
|
9.8 |
CRITICAL
Network
|
bss_continuity_cms_project
|
bss_continuty_cms
|
BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2014-3449
|
2024-11-21 11:08 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280575
|
9.8 |
CRITICAL
Network
|
bss_continuity_cms_project
|
bss_continuty_cms
|
BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-3448
|
2024-11-21 11:08 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280576
|
7.5 |
HIGH
Network
|
bss_continuity_cms_project
|
bss_continuty_cms
|
BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2014-3447
|
2024-11-21 11:08 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280577
|
6.1 |
MEDIUM
Network
|
marked_project
|
marked
|
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codebloc…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3743
|
2024-11-21 11:08 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280578
|
6.5 |
MEDIUM
Network
|
redhat
|
satellite
|
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted c…
|
CWE-352
Origin Validation Error
|
CVE-2014-3590
|
2024-11-21 11:08 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280579
|
8.1 |
HIGH
Network
|
redhat
|
edeploy jboss_enterprise_web_server
|
eDeploy has tmp file race condition flaws
|
CWE-362
Race Condition
|
CVE-2014-3701
|
2024-11-21 11:08 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280580
|
9.8 |
CRITICAL
Network
|
redhat
|
edeploy jboss_enterprise_web_server
|
eDeploy has RCE via cPickle deserialization of untrusted data
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2014-3699
|
2024-11-21 11:08 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|