|
277591
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7827
|
2024-11-21 11:18 |
2015-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277592
|
- |
|
advantech
|
eki-1200_gateway_series_firmware
|
Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-8385
|
2024-11-21 11:18 |
2015-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277593
|
- |
|
apache
|
activemq
|
Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unsp…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8110
|
2024-11-21 11:18 |
2015-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277594
|
- |
|
zohocorp
|
manageengine_opmanager
|
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attacke…
|
CWE-89
SQL Injection
|
CVE-2014-7864
|
2024-11-21 11:18 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277595
|
- |
|
cisco
|
hostscan_engine anyconnect_secure_mobility_client
|
Cross-site scripting (XSS) vulnerability in Cisco AnyConnect Secure Mobility Client 3.1(.02043) and earlier and Cisco HostScan Engine 3.1(.05183) and earlier allows remote attackers to inject arbitra…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8021
|
2024-11-21 11:18 |
2015-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277596
|
- |
|
cisco
|
nx-os
|
The TACACS+ command-authorization implementation in Cisco NX-OS allows local users to cause a denial of service (device reload) via a long CLI command, aka Bug ID CSCur54182.
|
CWE-20
Improper Input Validation
|
CVE-2014-8013
|
2024-11-21 11:18 |
2015-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277597
|
- |
|
hp
|
sitescope
|
Unspecified vulnerability in HP SiteScope 11.1x and 11.2x allows remote authenticated users to gain privileges via unknown vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7882
|
2024-11-21 11:18 |
2015-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277598
|
- |
|
qpr
|
portal
|
QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8268
|
2024-11-21 11:18 |
2015-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277599
|
- |
|
qpr
|
portal
|
Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the RID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8267
|
2024-11-21 11:18 |
2015-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277600
|
- |
|
qpr
|
portal
|
Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2)…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8266
|
2024-11-21 11:18 |
2015-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|