|
281941
|
- |
|
plogger
|
plogger
|
Plogger 1.0 RC1 and earlier, when the Lucid theme is used, does not assign new values for certain codes, which makes it easier for remote attackers to bypass the CAPTCHA protection mechanism via a se…
|
CWE-254
7PK - Security Features
|
CVE-2014-2224
|
2024-11-21 11:05 |
2014-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281942
|
- |
|
videowhisper
|
videowhisper_live_streaming_integration
|
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attac…
|
CWE-200
Information Exposure
|
CVE-2014-1908
|
2024-11-21 11:05 |
2014-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281943
|
- |
|
videowhisper
|
videowhisper_live_streaming_integration
|
Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code b…
|
CWE-77
Command Injection
|
CVE-2014-1905
|
2024-11-21 11:05 |
2014-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281944
|
- |
|
facebook
|
hiphop_virtual_machine
|
Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2209
|
2024-11-21 11:05 |
2014-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281945
|
- |
|
facebook
|
hiphop_virtual_machine
|
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbit…
|
CWE-94
Code Injection
|
CVE-2014-2208
|
2024-11-21 11:05 |
2014-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281946
|
- |
|
telerik
|
ui_for_asp.net_ajax
|
Absolute path traversal vulnerability in the RadAsyncUpload control in the RadControls in Telerik UI for ASP.NET AJAX before Q3 2012 SP2 allows remote attackers to write to arbitrary files, and conse…
|
CWE-22
Path Traversal
|
CVE-2014-2217
|
2024-11-21 11:05 |
2014-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281947
|
- |
|
unitedplanet
|
intrexx
|
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2026
|
2024-11-21 11:05 |
2014-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281948
|
- |
|
huawei
|
p2-6011_firmware
|
The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary memory locations via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2273
|
2024-11-21 11:05 |
2014-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281949
|
- |
|
infoware
|
mapsuite
|
Server-side request forgery (SSRF) vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to trigger requests to intranet servers via unspecifi…
|
NVD-CWE-Other
|
CVE-2014-2233
|
2024-11-21 11:05 |
2014-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281950
|
- |
|
infoware
|
mapsuite
|
Absolute path traversal vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-21
Pathname Traversal and Equivalence Errors
|
CVE-2014-2232
|
2024-11-21 11:05 |
2014-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|