|
277741
|
- |
|
cisco
|
openh264
|
Use-after-free vulnerability in decode_slice.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-8002
|
2024-11-21 11:18 |
2014-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277742
|
- |
|
cisco
|
openh264
|
Buffer overflow in decode.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-8001
|
2024-11-21 11:18 |
2014-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277743
|
- |
|
arubanetworks
|
airwave
|
The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8368
|
2024-11-21 11:18 |
2014-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277744
|
- |
|
arubanetworks
|
clearpass_policy_manager
|
SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL commands via unspecifi…
|
CWE-89
SQL Injection
|
CVE-2014-8367
|
2024-11-21 11:18 |
2014-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277745
|
- |
|
redhat
|
resteasy
|
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external en…
|
CWE-20
Improper Input Validation
|
CVE-2014-7839
|
2024-11-21 11:18 |
2014-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277746
|
- |
|
liferay
|
liferay_portal
|
Cross-site scripting (XSS) vulnerability in Liferay Portal Enterprise Edition (EE) 6.2 SP8 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the _20_body parame…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8349
|
2024-11-21 11:18 |
2014-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277747
|
- |
|
openstack fedoraproject redhat
|
neutron fedora openstack
|
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
|
CWE-20 CWE-399
Improper Input Validation Resource Management Errors
|
CVE-2014-7821
|
2024-11-21 11:18 |
2014-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277748
|
- |
|
canonical debian gnu opensuse
|
ubuntu_linux debian_linux glibc opensuse
|
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containin…
|
CWE-20
Improper Input Validation
|
CVE-2014-7817
|
2024-11-21 11:18 |
2014-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277749
|
- |
|
moodle
|
moodle
|
lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error mes…
|
CWE-200
Information Exposure
|
CVE-2014-7848
|
2024-11-21 11:18 |
2014-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277750
|
- |
|
moodle
|
moodle
|
iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial of service (resource consumption) by triggering t…
|
CWE-399
Resource Management Errors
|
CVE-2014-7847
|
2024-11-21 11:18 |
2014-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|