|
277861
|
5.3 |
MEDIUM
Network
|
dropbox
|
dropbox_sdk
|
Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.
|
CWE-200
Information Exposure
|
CVE-2014-8889
|
2024-11-21 11:19 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277862
|
9.8 |
CRITICAL
Network
|
codeigniter
|
codeigniter
|
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
|
CWE-310
Cryptographic Issues
|
CVE-2014-8686
|
2024-11-21 11:19 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277863
|
9.8 |
CRITICAL
Network
|
kohanaframework codeigniter
|
kohana codeigniter
|
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by lever…
|
CWE-310
Cryptographic Issues
|
CVE-2014-8684
|
2024-11-21 11:19 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277864
|
5.3 |
MEDIUM
Network
|
soplanning
|
soplanning
|
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create a…
|
CWE-94 CWE-284
Code Injection Improper Access Control
|
CVE-2014-8677
|
2024-11-21 11:19 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277865
|
5.3 |
MEDIUM
Network
|
soplanning
|
soplanning
|
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL pa…
|
CWE-22
Path Traversal
|
CVE-2014-8676
|
2024-11-21 11:19 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277866
|
7.5 |
HIGH
Network
|
soplanning
|
soplanning
|
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force at…
|
CWE-200
Information Exposure
|
CVE-2014-8675
|
2024-11-21 11:19 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277867
|
7.8 |
HIGH
Local
|
avm
|
fritz\!box_6810_lte_firmware fritz\!box_6840_lte_firmware
|
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.
|
CWE-94
Code Injection
|
CVE-2014-8872
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277868
|
7.8 |
HIGH
Local
|
corel
|
coreldraw_photo_paint coreldraw paint_shop_pro painter pdf_fusion
|
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2014-8393
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277869
|
8.8 |
HIGH
Network
|
ibm
|
urbancode_deploy
|
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
|
CWE-352
Origin Validation Error
|
CVE-2014-8900
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277870
|
7.5 |
HIGH
Network
|
sap
|
hybris
|
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5…
|
CWE-22
Path Traversal
|
CVE-2014-8871
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|