|
282671
|
- |
|
python
|
pyxdg
|
Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to …
|
CWE-59
Link Following
|
CVE-2014-1624
|
2024-11-21 11:04 |
2014-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282672
|
- |
|
python
|
rply
|
The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof cache data by pre-creating a temporary rply-*.json file with a predictable name.
|
NVD-CWE-Other
|
CVE-2014-1604
|
2024-11-21 11:04 |
2014-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282673
|
- |
|
citrix
|
gotomeeting
|
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens …
|
CWE-200
Information Exposure
|
CVE-2014-1664
|
2024-11-21 11:04 |
2014-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282674
|
- |
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: thi…
|
CWE-79
Cross-site Scripting
|
CVE-2014-1607
|
2024-11-21 11:04 |
2014-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282675
|
- |
|
xen
|
xen
|
The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix and (2) PHYSDEVOP_release_msix operations, which a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1666
|
2024-11-21 11:04 |
2014-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282676
|
- |
|
xen
|
xen
|
The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest…
|
CWE-399
Resource Management Errors
|
CVE-2014-1642
|
2024-11-21 11:04 |
2014-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282677
|
- |
|
checkpoint
|
session_authentication_agent
|
Check Point Session Authentication Agent allows remote attackers to obtain sensitive information (user credentials) via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2014-1673
|
2024-11-21 11:04 |
2014-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282678
|
- |
|
checkpoint
|
management_server security_gateway
|
Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, whic…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1672
|
2024-11-21 11:04 |
2014-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282679
|
- |
|
galen_charlton
|
marc-xml
|
XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1626
|
2024-11-21 11:04 |
2014-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282680
|
- |
|
dell
|
kace_k1200s_systems_management_appliance kace_k1100s_systems_management_appliance kace_k1000_systems_management_appliance_software kace_k1000_systems_management_appliance kace_k1000_syste…
|
Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the macAddress elem…
|
CWE-89
SQL Injection
|
CVE-2014-1671
|
2024-11-21 11:04 |
2014-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|