|
281921
|
5.5 |
MEDIUM
Local
|
numpy
|
numpy
|
__init__.py in f2py in NumPy before 1.8.1 allows local users to write to arbitrary files via a symlink attack on a temporary file.
|
CWE-20
Improper Input Validation
|
CVE-2014-1858
|
2024-11-21 11:05 |
2018-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281922
|
9.8 |
CRITICAL
Network
|
tapatalk
|
tapatalk
|
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API r…
|
CWE-89
SQL Injection
|
CVE-2014-2023
|
2024-11-21 11:05 |
2017-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281923
|
7.1 |
HIGH
Local
|
perltidy_project
|
perltidy
|
The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive information or write to arbitrary files via a symlink attack, related to use of the tmpn…
|
CWE-284
Improper Access Control
|
CVE-2014-2277
|
2024-11-21 11:05 |
2017-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281924
|
8.1 |
HIGH
Network
|
percona
|
toolkit
|
The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or execute arbitrary code by leveraging use of HTTP to…
|
CWE-200
Information Exposure
|
CVE-2014-2029
|
2024-11-21 11:05 |
2017-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281925
|
6.1 |
MEDIUM
Network
|
viprinet
|
multichannel_vpn_router_300_firmware
|
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to inject arbitrary web script or HTML via the usernam…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2045
|
2024-11-21 11:05 |
2017-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281926
|
6.5 |
MEDIUM
Network
|
cisco
|
ios_xe ios
|
The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attack…
|
CWE-20
Improper Input Validation
|
CVE-2014-2146
|
2024-11-21 11:05 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281927
|
- |
|
apache
|
tapestry
|
Apache Tapestry before 5.3.6 relies on client-side object storage without checking whether a client has modified an object, which allows remote attackers to cause a denial of service (resource consum…
|
CWE-399
Resource Management Errors
|
CVE-2014-1972
|
2024-11-21 11:05 |
2015-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281928
|
- |
|
impresscms
|
impresscms
|
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_pat…
|
CWE-22
Path Traversal
|
CVE-2014-1836
|
2024-11-21 11:05 |
2015-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281929
|
- |
|
cisco
|
telepresence_tc_software telepresence_te_software
|
Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obtain root privileges by sending packets on the local…
|
CWE-284
Improper Access Control
|
CVE-2014-2174
|
2024-11-21 11:05 |
2015-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281930
|
- |
|
y-cam
|
ycb004_firmware ycb002_firmware yck002_firmware yck003_firmware yceb03_firmware ycb001_firmware ycblhd5_firmware ycblb3_firmware ycblb3 ycb003_firmware ycw003_firmware
|
Multiple cross-site scripting (XSS) vulnerabilities in Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD…
|
CWE-79
Cross-site Scripting
|
CVE-2014-1902
|
2024-11-21 11:05 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|