|
282001
|
- |
|
intercom
|
web_kyukincho
|
Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-2006
|
2024-11-21 11:05 |
2014-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282002
|
6.8 |
MEDIUM
Physics
|
sophos
|
enterprise_console
|
Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically…
|
CWE-287
Improper Authentication
|
CVE-2014-2005
|
2024-11-21 11:05 |
2014-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282003
|
- |
|
jreast
|
jr_east_japan
|
The East Japan Railway Company JR East Japan application before 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive inf…
|
CWE-310
Cryptographic Issues
|
CVE-2014-2001
|
2024-11-21 11:05 |
2014-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282004
|
- |
|
cisco
|
adaptive_security_appliance_software
|
The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information via a crafted JavaScript file, aka Bug I…
|
NVD-CWE-noinfo
|
CVE-2014-2151
|
2024-11-21 11:05 |
2014-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282005
|
- |
|
ntt
|
050_plus
|
The NTT 050 plus application before 4.2.1 for Android allows attackers to obtain sensitive information by leveraging the ability to read system log files.
|
CWE-200
Information Exposure
|
CVE-2014-2000
|
2024-11-21 11:05 |
2014-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282006
|
- |
|
iij
|
seil\%2fturbo_firmware seil\/turbo seil\%2fneu_2fe_plus_firmware seil\/neu_2fe_plus seil\%2fx86_firmware seil\/x86 seil\%2fx2_firmware seil\/x2 seil\%2fx1_firmware seil\/x1…
|
The PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 routers 1.00 through 3.10, SEIL/X1 routers 1.00 through 4.50, SEIL/X2 routers 1.00 through 4.50, SEIL/B1 routers 1.00 through 4.50, SEIL/Turbo rou…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-2004
|
2024-11-21 11:05 |
2014-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282007
|
- |
|
justsystems
|
just_online_update ichitaro
|
JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execut…
|
CWE-20
Improper Input Validation
|
CVE-2014-2003
|
2024-11-21 11:05 |
2014-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282008
|
- |
|
cisco
|
ios_xr asr_9001 asr_9006 asr_9010 asr_9904 asr_9912 asr_9922
|
Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (NP chip and line card reload) via malformed IPv6 pa…
|
CWE-399
Resource Management Errors
|
CVE-2014-2176
|
2024-11-21 11:05 |
2014-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282009
|
- |
|
c-board_moyuku_project
|
c-board_moyuku
|
Cross-site scripting (XSS) vulnerability in C-BOARD Moyuku 1.01b6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-2002
|
2024-11-21 11:05 |
2014-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282010
|
- |
|
microsoft
|
lync_server
|
Cross-site scripting (XSS) vulnerability in the Web Components Server in Microsoft Lync Server 2010 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted URL containin…
|
CWE-79
Cross-site Scripting
|
CVE-2014-1823
|
2024-11-21 11:05 |
2014-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|