|
280971
|
7.5 |
HIGH
Network
|
askpop3d_project
|
askpop3d
|
A Denial of Service vulnerability exists in askpop3d 0.7.7 in free (pszQuery),
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3208
|
2024-11-21 11:07 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280972
|
6.1 |
MEDIUM
Network
|
keplerproject
|
cgilua
|
The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a brute force attack. NO…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2014-2875
|
2024-11-21 11:07 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280973
|
8.8 |
HIGH
Network
|
web2project
|
web2project
|
Multiple SQL injection vulnerabilities in web2Project 3.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search_string parameter in the contacts module to …
|
CWE-89
SQL Injection
|
CVE-2014-3119
|
2024-11-21 11:07 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280974
|
6.1 |
MEDIUM
Network
|
infoware
|
mapsuite
|
Cross-site scripting (XSS) vulnerability in infoware MapSuite MapAPI 1.0.x before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-2843
|
2024-11-21 11:07 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280975
|
5.9 |
MEDIUM
Network
|
lwp\
|
\
|
The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS…
|
CWE-295
Improper Certificate Validation
|
CVE-2014-3230
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280976
|
9.8 |
CRITICAL
Network
|
fishshell
|
fish
|
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as d…
|
CWE-20
Improper Input Validation
|
CVE-2014-2914
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280977
|
7.0 |
HIGH
Local
|
fishshell
|
fish
|
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable…
|
CWE-362
Race Condition
|
CVE-2014-2906
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280978
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2898
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280979
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote attackers to have unspecified impact via a crafted HMA…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2897
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280980
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an o…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2896
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|