|
281581
|
- |
|
imember360
|
imember360
|
Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3842
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281582
|
- |
|
tech-banker
|
contact_bank
|
Cross-site scripting (XSS) vulnerability in the Contact Bank plugin before 2.0.20 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Label field, related to form lay…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3841
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281583
|
- |
|
dotclear
|
dotclear
|
SQL injection vulnerability in admin/categories.php in Dotclear before 2.6.3 allows remote authenticated users with the manage categories permission to execute arbitrary SQL commands via the categori…
|
CWE-89
SQL Injection
|
CVE-2014-3783
|
2024-11-21 11:08 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281584
|
- |
|
libgadu
|
libgadu
|
libgadu before 1.11.4 and 1.12.0 before 1.12.0-rc3, as used in Pidgin and other products, allows remote Gadu-Gadu file relay servers to cause a denial of service (memory overwrite) or possibly execut…
|
CWE-20
Improper Input Validation
|
CVE-2014-3775
|
2024-11-21 11:08 |
2014-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281585
|
- |
|
barracudadrive realtimelogic
|
barracudadrive
|
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) role parameter to roles.lsp, (2) name para…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3808
|
2024-11-21 11:08 |
2014-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281586
|
- |
|
barracudadrive
|
barracudadrive
|
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) blog, (2) bloggeruser, or (3) bloggerpasswd param…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3807
|
2024-11-21 11:08 |
2014-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281587
|
- |
|
vmturbo
|
operations_manager
|
Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the xml_path parameter.
|
CWE-22
Path Traversal
|
CVE-2014-3806
|
2024-11-21 11:08 |
2014-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281588
|
- |
|
google
|
chrome
|
The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT…
|
CWE-200
Information Exposure
|
CVE-2014-3803
|
2024-11-21 11:08 |
2014-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281589
|
- |
|
microsoft
|
debug_interface_access_software_development_kit visual_studio
|
msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspecified variable before use in calculating a dynamic-…
|
CWE-20
Improper Input Validation
|
CVE-2014-3802
|
2024-11-21 11:08 |
2014-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281590
|
- |
|
beetel
|
450tc2_router_firmware 450tc2_router
|
Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authentication of administrators for requests that change…
|
CWE-352
Origin Validation Error
|
CVE-2014-3792
|
2024-11-21 11:08 |
2014-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|