|
277841
|
9.8 |
CRITICAL
Network
|
synacor
|
zimbra_collaboration_server
|
Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.
|
CWE-78
OS Command
|
CVE-2014-8563
|
2024-11-21 11:19 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277842
|
7.5 |
HIGH
Network
|
lexmark
|
markvision_enterprise
|
Directory traversal vulnerability in the ReportDownloadServlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2014-8742
|
2024-11-21 11:19 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277843
|
9.8 |
CRITICAL
Network
|
lexmark
|
markvision_enterprise
|
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2014-8741
|
2024-11-21 11:19 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277844
|
9.8 |
CRITICAL
Network
|
soplanning
|
soplanning
|
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online Planning (SOPPlanning)before 1.33.
|
CWE-89
SQL Injection
|
CVE-2014-8673
|
2024-11-21 11:19 |
2020-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277845
|
5.4 |
MEDIUM
Network
|
soplanning
|
soplanning
|
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in nb_mois and mb_ligness and the debug GET parameter to export.ph…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8674
|
2024-11-21 11:19 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277846
|
9.8 |
CRITICAL
Network
|
cloudfastpath
|
netcharts_server
|
Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unsp…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-8516
|
2024-11-21 11:19 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277847
|
9.8 |
CRITICAL
Network
|
requests-kerberos_project debian
|
requests-kerberos debian_linux
|
python-requests-Kerberos through 0.5 does not handle mutual authentication
|
CWE-287
Improper Authentication
|
CVE-2014-8650
|
2024-11-21 11:19 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277848
|
6.5 |
MEDIUM
Network
|
imagemagick debian
|
imagemagick debian_linux
|
imagemagick 6.8.9.6 has remote DOS via infinite loop
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2014-8561
|
2024-11-21 11:19 |
2019-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277849
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-815_firmware
|
The remote administration interface in D-Link DIR-815 devices with firmware before 2.03.B02 allows remote attackers to execute arbitrary commands via vectors related to an "HTTP command injection iss…
|
CWE-77
Command Injection
|
CVE-2014-8888
|
2024-11-21 11:19 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277850
|
8.1 |
HIGH
Network
|
unify
|
openstage_sip openscape_desk_phone_ip_sip
|
The web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 generates session cookies with insufficient entropy, which makes…
|
CWE-331
Insufficient Entropy
|
CVE-2014-8422
|
2024-11-21 11:19 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|