|
282661
|
- |
|
otrs
|
otrs
|
SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before 3.1.19, 3.2.x before 3.2.14, and 3.3.x before 3.3.4 allows…
|
CWE-89
SQL Injection
|
CVE-2014-1471
|
2024-11-21 11:04 |
2014-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282662
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metac…
|
CWE-20
Improper Input Validation
|
CVE-2014-1610
|
2024-11-21 11:04 |
2014-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282663
|
- |
|
media5
|
mediatrix_voip_gateway_4402_firmware mediatrix_voip_gateway
|
Cross-site scripting (XSS) vulnerability in login.esp in the Web Management Interface in Media5 Mediatrix 4402 VoIP Gateway with firmware Dgw 1.1.13.186 and earlier allows remote attackers to inject …
|
CWE-79
Cross-site Scripting
|
CVE-2014-1612
|
2024-11-21 11:04 |
2014-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282664
|
- |
|
anonymous_posting_project
|
anonymous_posting
|
Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the contact name field.
|
CWE-79
Cross-site Scripting
|
CVE-2014-1611
|
2024-11-21 11:04 |
2014-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282665
|
- |
|
skybluecanvas
|
skybluecanvas
|
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2014-1683
|
2024-11-21 11:04 |
2014-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282666
|
- |
|
openbsd
|
openssh
|
The hash_buffer function in schnorr.c in OpenSSH through 6.4, when Makefile.inc is modified to enable the J-PAKE protocol, does not initialize certain data structures, which might allow remote attack…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-1692
|
2024-11-21 11:04 |
2014-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282667
|
- |
|
google
|
chrome
|
Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.102 have unknown impact and attack vectors, related to 12 "security fixes [that were not] either contributed by external researc…
|
NVD-CWE-noinfo
|
CVE-2014-1681
|
2024-11-21 11:04 |
2014-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282668
|
- |
|
debian
|
axiom
|
axiom-test.sh in axiom 20100701-1.1 uses tempfile to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite …
|
CWE-59
Link Following
|
CVE-2014-1640
|
2024-11-21 11:04 |
2014-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282669
|
- |
|
debian
|
syncevolution
|
syncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows …
|
CWE-59
Link Following
|
CVE-2014-1639
|
2024-11-21 11:04 |
2014-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282670
|
- |
|
debian
|
localepurge
|
(1) debian/postrm and (2) debian/localepurge.config in localepurge before 0.7.3.2 use tempfile to create a safe temporary file but appends a suffix to the original filename and writes to this new fil…
|
CWE-59
Link Following
|
CVE-2014-1638
|
2024-11-21 11:04 |
2014-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|