|
277471
|
- |
|
drupal
|
custom_search_module
|
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" pe…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8745
|
2024-11-21 11:19 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277472
|
- |
|
drupal
|
nivo_slider
|
Cross-site scripting (XSS) vulnerability in the Nivo Slider module 7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users with the "administer nivo slider" permission to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8744
|
2024-11-21 11:19 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277473
|
- |
|
drupal
|
maestro
|
Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8743
|
2024-11-21 11:19 |
2014-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277474
|
9.1 |
CRITICAL
Network
|
redhat
|
cloudforms_management_engine
|
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.
|
CWE-295
Improper Certificate Validation
|
CVE-2014-8164
|
2024-11-21 11:18 |
2022-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277475
|
8.1 |
HIGH
Network
|
google
|
android
|
btif/src/btif_dm.c in Android before 5.1 does not properly enforce the temporary nature of a Bluetooth pairing, which allows user-assisted remote attackers to bypass intended access restrictions via …
|
CWE-863
Incorrect Authorization
|
CVE-2014-7914
|
2024-11-21 11:18 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277476
|
4.6 |
MEDIUM
Physics
|
google
|
android
|
Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitr…
|
CWE-22
Path Traversal
|
CVE-2014-7951
|
2024-11-21 11:18 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277477
|
9.8 |
CRITICAL
Network
|
zend redhat fedoraproject
|
zend_framework enterprise_linux fedora
|
SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands…
|
CWE-89
SQL Injection
|
CVE-2014-8089
|
2024-11-21 11:18 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277478
|
6.5 |
MEDIUM
Network
|
libtiff
|
libtiff
|
LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.
|
CWE-787
Out-of-bounds Write
|
CVE-2014-8128
|
2024-11-21 11:18 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277479
|
7.8 |
HIGH
Local
|
claris
|
filemaker_pro filemaker_pro_advanced
|
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevat…
|
CWE-287
Improper Authentication
|
CVE-2014-8347
|
2024-11-21 11:18 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277480
|
7.5 |
HIGH
Network
|
zohocorp
|
manageengine_it360 manageengine_opmanager manageengine_applications_manager
|
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not proper…
|
CWE-200
Information Exposure
|
CVE-2014-7863
|
2024-11-21 11:18 |
2020-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|