|
277711
|
- |
|
phpmyadmin
|
phpmyadmin
|
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long p…
|
CWE-399
Resource Management Errors
|
CVE-2014-9218
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277712
|
- |
|
torch_gmbh
|
graylog2
|
Graylog2 before 0.92 allows remote attackers to bypass LDAP authentication via crafted wildcards.
|
CWE-287
Improper Authentication
|
CVE-2014-9217
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277713
|
- |
|
plex
|
media_server
|
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9304
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277714
|
- |
|
entrypass
|
n5200_active_network_control_panel
|
EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or…
|
CWE-200
Information Exposure
|
CVE-2014-9303
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277715
|
- |
|
alfresco
|
community_edition
|
Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attacke…
|
NVD-CWE-Other
|
CVE-2014-9302
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277716
|
- |
|
alfresco
|
alfresco
|
Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger outbound requests to intranet servers, conduct port…
|
NVD-CWE-Other
|
CVE-2014-9301
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277717
|
- |
|
alfresco
|
alfresco
|
Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition before 5.0.a allows remote attackers to …
|
CWE-352
Origin Validation Error
|
CVE-2014-9300
|
2024-11-21 11:20 |
2014-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277718
|
- |
|
mantisbt
|
mantisbt
|
MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging knowledge of a CAPT…
|
CWE-284
Improper Access Control
|
CVE-2014-9117
|
2024-11-21 11:20 |
2014-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277719
|
- |
|
openbsd
|
openssh
|
The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in th…
|
CWE-287
Improper Authentication
|
CVE-2014-9278
|
2024-11-21 11:20 |
2014-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277720
|
- |
|
jrss_widget_project
|
jrss_widget
|
Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress allows remote attackers to trigger outbound requests and enumerate open ports via…
|
NVD-CWE-Other
|
CVE-2014-9292
|
2024-11-21 11:20 |
2014-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|