|
281381
|
- |
|
misli
|
misli.com_app
|
The Misli.com application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted cer…
|
CWE-310
Cryptographic Issues
|
CVE-2014-2992
|
2024-11-21 11:07 |
2014-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281382
|
- |
|
xcloner
|
xcloner
|
XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the dbbackup_co…
|
CWE-94
Code Injection
|
CVE-2014-2996
|
2024-11-21 11:07 |
2014-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281383
|
- |
|
siemens
|
simatic_s7_cpu_1200_firmware simatic_s7_cpu-1211c simatic_s7_cpu_1212c simatic_s7_cpu_1214c simatic_s7_cpu_1215c simatic_s7_cpu_1217c
|
CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2014-2909
|
2024-11-21 11:07 |
2014-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281384
|
- |
|
siemens
|
simatic_s7_cpu_1200_firmware simatic_s7_cpu-1211c simatic_s7_cpu_1212c simatic_s7_cpu_1214c simatic_s7_cpu_1215c simatic_s7_cpu_1217c
|
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2908
|
2024-11-21 11:07 |
2014-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281385
|
- |
|
xen
|
xen
|
Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of service (host or guest crash) via unspecified vecto…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2915
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281386
|
- |
|
wireshark
|
wireshark
|
The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to …
|
NVD-CWE-noinfo
|
CVE-2014-2907
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281387
|
- |
|
drupal debian
|
drupal debian_linux
|
Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input informati…
|
CWE-200
Information Exposure
|
CVE-2014-2983
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281388
|
- |
|
sixnet
|
sixview_manager
|
Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 18081.
|
CWE-22
Path Traversal
|
CVE-2014-2976
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281389
|
- |
|
qemu
|
qemu
|
Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE command that triggers a…
|
CWE-189
Numeric Errors
|
CVE-2014-2894
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281390
|
- |
|
opensuse llvm
|
opensuse clang
|
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directo…
|
CWE-59
Link Following
|
CVE-2014-2893
|
2024-11-21 11:07 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|