|
277111
|
9.8 |
CRITICAL
Network
|
seagate
|
business_nas_firmware
|
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session token…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2014-8687
|
2024-11-21 11:19 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277112
|
6.2 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
The JPEG decoder in ImageMagick before 6.8.9-9 allows local users to cause a denial of service (out-of-bounds memory access and crash).
|
CWE-125
Out-of-bounds Read
|
CVE-2014-8716
|
2024-11-21 11:19 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277113
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
DCM decode in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
|
CWE-125
Out-of-bounds Read
|
CVE-2014-8562
|
2024-11-21 11:19 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277114
|
7.5 |
HIGH
Network
|
huawei
|
ac6605_firmware acu_firmware s_series_firmware s5300_firmware s5700_firmware s6700_firmware s6300_firmware s7700_firmware s9700_firmware s9300_firmware s9300e_firmware
|
Huawei AC6605 with software V200R001C00; AC6605 with software V200R002C00; ACU with software V200R001C00; ACU with software V200R002C00; S2300, S3300, S2700, S3700 with software V100R006C05 and earli…
|
CWE-20
Improper Input Validation
|
CVE-2014-8572
|
2024-11-21 11:19 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277115
|
3.3 |
LOW
Local
|
huawei
|
ascend_p6_edge-u00_firmware ascend_p6_edge-t00_firmware ascend_p6_edge-c00_firmware
|
Apps on Huawei Ascend P6 mobile phones with software EDGE-U00 V100R001C17B508SP01 and earlier versions before V100R001C17B508SP02; EDGE-T00 V100R001C01B508SP01 and earlier versions before V100R001C01…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8571
|
2024-11-21 11:19 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277116
|
5.3 |
MEDIUM
Network
|
huawei
|
s9300_firmware s9303_firmware s9306_firmware s9312_firmware s7700_firmware s7703_firmware s7706_firmware s7712_firmware s9300e_firmware s9303e_firmware s9306e_firmware
|
Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with soft…
|
CWE-200
Information Exposure
|
CVE-2014-8570
|
2024-11-21 11:19 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277117
|
9.8 |
CRITICAL
Network
|
phpmemcachedadmin_project
|
phpmemcachedadmin
|
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2014-8731
|
2024-11-21 11:19 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277118
|
5.3 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation …
|
CWE-200
Information Exposure
|
CVE-2014-8723
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277119
|
7.5 |
HIGH
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.x…
|
CWE-200
Information Exposure
|
CVE-2014-8722
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277120
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluck
|
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8708
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|