|
277771
|
- |
|
adobe
|
acrobat_reader acrobat
|
Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently write to file…
|
CWE-362
Race Condition
|
CVE-2014-9150
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277772
|
- |
|
linux
|
linux_kernel
|
The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel through 3.17.4 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local …
|
CWE-17
Code
|
CVE-2014-9090
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277773
|
- |
|
linux
|
linux_kernel
|
The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by l…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8989
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277774
|
- |
|
debian mantisbt
|
debian_linux mantisbt
|
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_se…
|
CWE-89
SQL Injection
|
CVE-2014-9089
|
2024-11-21 11:20 |
2014-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277775
|
- |
|
check_diskio_project
|
check_diskio
|
The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_statu…
|
CWE-18
Source Code
|
CVE-2014-8994
|
2024-11-21 11:20 |
2014-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277776
|
- |
|
openvpn
|
openvpn_access_server
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of a…
|
CWE-352
Origin Validation Error
|
CVE-2014-9104
|
2024-11-21 11:20 |
2014-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277777
|
- |
|
kunena
|
kunena
|
Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) index value of an array …
|
CWE-79
Cross-site Scripting
|
CVE-2014-9103
|
2024-11-21 11:20 |
2014-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277778
|
- |
|
kunena
|
kunena
|
Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users to execute arbitrary SQL commands via the index value in an array parameter, a…
|
CWE-89
SQL Injection
|
CVE-2014-9102
|
2024-11-21 11:20 |
2014-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277779
|
- |
|
skalfa oxwall
|
skadate_lite oxwall
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attackers to hijack the authentication of administrator…
|
CWE-352
Origin Validation Error
|
CVE-2014-9101
|
2024-11-21 11:20 |
2014-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277780
|
- |
|
whydowork_adsense_project
|
whydowork_adsense
|
Cross-site scripting (XSS) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the idcode parameter in the whydowork_ads…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9100
|
2024-11-21 11:20 |
2014-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|