|
279771
|
- |
|
microsoft
|
active_directory_federation_services
|
Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-6331
|
2024-11-21 11:14 |
2014-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279772
|
- |
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer 7 through 11 allows remote attackers to obtain sensitive clipboard information via a crafted web site, aka "Internet Explorer Clipboard Information Disclosure Vulnerabilit…
|
CWE-200
Information Exposure
|
CVE-2014-6323
|
2024-11-21 11:14 |
2014-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279773
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8
|
The Windows Audio service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow…
|
CWE-20
Improper Input Validation
|
CVE-2014-6322
|
2024-11-21 11:14 |
2014-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279774
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8 windows_server_2003
|
Schannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8…
|
CWE-94
Code Injection
|
CVE-2014-6321
|
2024-11-21 11:14 |
2014-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279775
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_8.1 windows_7 windows_rt_8.1 windows_vista windows_8 windows_server_2003
|
Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows …
|
CWE-129
Improper Validation of Array Index
|
CVE-2014-6317
|
2024-11-21 11:14 |
2014-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279776
|
- |
|
microsoft
|
windows_server_2008 windows_server_2012 windows_rt windows_8.1 windows_8 windows_vista windows_rt_8.1 windows_7
|
The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, an…
|
CWE-287
Improper Authentication
|
CVE-2014-6318
|
2024-11-21 11:14 |
2014-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279777
|
- |
|
opensuse phpmyadmin
|
opensuse phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arb…
|
CWE-79
Cross-site Scripting
|
CVE-2014-6300
|
2024-11-21 11:14 |
2014-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279778
|
- |
|
arubanetworks
|
clearpass
|
Cross-site request forgery (CSRF) vulnerability in the Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to hijack the authentication of a logged …
|
CWE-79
Cross-site Scripting
|
CVE-2014-6623
|
2024-11-21 11:14 |
2014-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279779
|
- |
|
arubanetworks
|
clearpass
|
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-6620
|
2024-11-21 11:14 |
2014-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279780
|
- |
|
exponentcms
|
exponent_cms
|
Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the src parameter in the search action to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2014-6635
|
2024-11-21 11:14 |
2014-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|