|
278431
|
- |
|
notify_project
|
notify
|
The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titl…
|
CWE-200
Information Exposure
|
CVE-2014-9154
|
2024-11-21 11:20 |
2014-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278432
|
- |
|
services_project
|
services
|
Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the callback parameter …
|
CWE-79
Cross-site Scripting
|
CVE-2014-9153
|
2024-11-21 11:20 |
2014-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278433
|
- |
|
services_project
|
services
|
The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess …
|
CWE-255
Credentials Management
|
CVE-2014-9152
|
2024-11-21 11:20 |
2014-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278434
|
- |
|
services_project
|
services
|
The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attac…
|
CWE-284
Improper Access Control
|
CVE-2014-9151
|
2024-11-21 11:20 |
2014-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278435
|
- |
|
mageia debian gnupg canonical
|
mageia debian_linux libksba ubuntu_linux gnupg
|
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or …
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2014-9087
|
2024-11-21 11:20 |
2014-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278436
|
- |
|
clamav
|
clamav
|
Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9050
|
2024-11-21 11:20 |
2014-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278437
|
- |
|
phpmyadmin opensuse
|
phpmyadmin opensuse
|
Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obt…
|
CWE-22
Path Traversal
|
CVE-2014-8961
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278438
|
- |
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8960
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278439
|
- |
|
opensuse phpmyadmin
|
opensuse phpmyadmin
|
Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allows remote authentica…
|
CWE-22
Path Traversal
|
CVE-2014-8959
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278440
|
- |
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8958
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|