|
283561
|
- |
|
python
|
python
|
Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file per…
|
CWE-362
Race Condition
|
CVE-2014-2667
|
2024-11-21 11:06 |
2014-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283562
|
- |
|
zend
|
zendopenid zend_framework
|
The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value i…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2684
|
2024-11-21 11:06 |
2014-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283563
|
- |
|
zend
|
zendrest zend_framework zendservice_slideshare zendservice_api zendservice_audioscrobbler zendservice_amazon zendservice_technorati zendservice_windowsazure zendopenid zend…
|
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService…
|
CWE-17
Code
|
CVE-2014-2683
|
2024-11-21 11:06 |
2014-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283564
|
- |
|
zend
|
zendrest zend_framework zendservice_slideshare zendservice_api zendservice_audioscrobbler zendservice_amazon zendservice_technorati zendservice_windowsazure zendopenid zend…
|
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService…
|
CWE-19
Data Processing Errors
|
CVE-2014-2682
|
2024-11-21 11:06 |
2014-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283565
|
- |
|
zend
|
zendrest zend_framework zendservice_slideshare zendservice_api zendservice_audioscrobbler zendservice_amazon zendservice_technorati zendservice_windowsazure zendopenid zend…
|
Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService…
|
CWE-19
Data Processing Errors
|
CVE-2014-2681
|
2024-11-21 11:06 |
2014-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283566
|
- |
|
accuenergy
|
axm-net acuvim_ii
|
The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.
|
CWE-200
Information Exposure
|
CVE-2014-2374
|
2024-11-21 11:06 |
2014-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283567
|
- |
|
accuenergy
|
axm-net acuvim_ii
|
The web server on the AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to bypass authentication and modify settings via a direct request to an unspecified U…
|
CWE-287
Improper Authentication
|
CVE-2014-2373
|
2024-11-21 11:06 |
2014-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283568
|
- |
|
t-mobile asus
|
tm-ac1900 rt_series_firmware
|
ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2014-2718
|
2024-11-21 11:06 |
2014-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283569
|
- |
|
fortinet
|
fortimanager fortianalyzer_firmware
|
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2336
|
2024-11-21 11:06 |
2014-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283570
|
- |
|
fortinet
|
fortianalyzer_firmware
|
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vecto…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2335
|
2024-11-21 11:06 |
2014-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|