|
281571
|
- |
|
imember360
|
imember360
|
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3848
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281572
|
- |
|
openstack
|
heat
|
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider templ…
|
CWE-200
Information Exposure
|
CVE-2014-3801
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281573
|
- |
|
pandasecurity
|
panda_av_pro_2014 panda_internet_security_2014 panda_global_protection_2014 panda_gold_protection
|
Unspecified vulnerability in Panda Gold Protection and Global Protection 2014 7.01.01 and earlier, Internet Security 2014 19.01.01 and earlier, and AV Pro 2014 13.01.01 and earlier allows local users…
|
NVD-CWE-noinfo
|
CVE-2014-3450
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281574
|
- |
|
nullsoft
|
winamp
|
Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malformed .FLV file, related to f263.w5s.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3442
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281575
|
- |
|
cogentdatahub
|
cogent_datahub
|
GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2014-3789
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281576
|
- |
|
cogentdatahub
|
cogent_datahub
|
Heap-based buffer overflow in the Web Server in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary code via a negative value in the Content-Length field…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3788
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281577
|
- |
|
flyingcart
|
flying_cart
|
Cross-site scripting (XSS) vulnerability in Flying Cart allows remote attackers to inject arbitrary web script or HTML via the p parameter to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3846
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281578
|
- |
|
tinymce
|
color_picker
|
Cross-site request forgery (CSRF) vulnerability in the TinyMCE Color Picker plugin before 1.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for requests that…
|
CWE-352
Origin Validation Error
|
CVE-2014-3845
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281579
|
- |
|
tinymce
|
color_picker
|
The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings via unspecified vectors. NOTE: some of these det…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3844
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281580
|
- |
|
zemanta
|
search_everything
|
Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vect…
|
CWE-352
Origin Validation Error
|
CVE-2014-3843
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|