|
280751
|
- |
|
redhat
|
conga
|
The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3521
|
2024-11-21 11:08 |
2014-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280752
|
- |
|
cisco
|
webex_meetings_server
|
Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive information by reading logs, aka Bug IDs CSCuq36417 and CSCuq40344.
|
CWE-200
Information Exposure
|
CVE-2014-3400
|
2024-11-21 11:08 |
2014-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280753
|
- |
|
cisco
|
adaptive_security_appliance_software
|
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-version information by reading the verbose response dat…
|
CWE-200
Information Exposure
|
CVE-2014-3398
|
2024-11-21 11:08 |
2014-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280754
|
- |
|
cisco
|
ios_xr asr_9000_rsp440_router asr_9001 asr_9006 asr_9010 asr_9904 asr_9912 asr_9922
|
Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3396
|
2024-11-21 11:08 |
2014-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280755
|
- |
|
openstack canonical redhat
|
keystone ubuntu_linux openstack
|
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpo…
|
CWE-200
Information Exposure
|
CVE-2014-3621
|
2024-11-21 11:08 |
2014-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280756
|
- |
|
cisco
|
webex_meetings_server
|
Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343.
|
CWE-20
Improper Input Validation
|
CVE-2014-3395
|
2024-11-21 11:08 |
2014-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280757
|
- |
|
redhat
|
hibernate_validator
|
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3558
|
2024-11-21 11:08 |
2014-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280758
|
- |
|
juniper
|
junos_pulse_secure_access_service
|
Cross-site scripting (XSS) vulnerability in the web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r6, 7.4 before 7.4r13, and 7.1 before 7.1r20 al…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3824
|
2024-11-21 11:08 |
2014-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280759
|
- |
|
juniper
|
junos_pulse_secure_access_service
|
The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 8.0 before 8.0r1, 7.4 before 7.4r5, and 7.1 before 7.1r18 allows remote attackers to conduct clickjacking attacks via unspe…
|
CWE-20
Improper Input Validation
|
CVE-2014-3823
|
2024-11-21 11:08 |
2014-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280760
|
- |
|
juniper
|
junos_pulse_access_control_service junos_pulse_secure_access_service
|
Cross-site scripting (XSS) vulnerability in the SSL VPN/UAC web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 7.1 before 7.1r16, 7.4 before 7.4r3, and 8.0 befo…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3820
|
2024-11-21 11:08 |
2014-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|