|
280791
|
5.5 |
MEDIUM
Local
|
rawstudio fedoraproject
|
rawstudio fedora
|
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-gr…
|
CWE-59
Link Following
|
CVE-2014-4978
|
2024-11-21 11:11 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280792
|
9.8 |
CRITICAL
Network
|
zend debian
|
zend_framework debian_linux
|
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2014-4914
|
2024-11-21 11:11 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280793
|
7.2 |
HIGH
Network
|
landesk
|
landesk_management_suite
|
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1)…
|
CWE-20
Improper Input Validation
|
CVE-2014-5362
|
2024-11-21 11:11 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280794
|
8.8 |
HIGH
Network
|
manageengine
|
servicedesk_plus assetexplorer supportcenter it360
|
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to ex…
|
CWE-22
Path Traversal
|
CVE-2014-5302
|
2024-11-21 11:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280795
|
8.8 |
HIGH
Network
|
manageengine
|
servicedesk_plus assetexplorer supportcenter it360
|
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
|
CWE-22
Path Traversal
|
CVE-2014-5301
|
2024-11-21 11:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280796
|
6.1 |
MEDIUM
Network
|
good
|
good_for_enterprise
|
Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4925
|
2024-11-21 11:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280797
|
5.4 |
MEDIUM
Network
|
telescopeapp
|
telescope
|
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted markdown.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5144
|
2024-11-21 11:11 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280798
|
9.8 |
CRITICAL
Network
|
snoopy redhat nagios
|
snoopy openstack nagios
|
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
|
CWE-77
Command Injection
|
CVE-2014-5009
|
2024-11-21 11:11 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280799
|
9.8 |
CRITICAL
Network
|
snoopy redhat debian
|
snoopy openstack debian_linux
|
Snoopy allows remote attackers to execute arbitrary commands.
|
CWE-77
Command Injection
|
CVE-2014-5008
|
2024-11-21 11:11 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280800
|
6.8 |
MEDIUM
Network
|
eucalyptus
|
eucalyptus
|
HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to bypass intended access restrictions and modify arbitrary (1) access key creden…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5040
|
2024-11-21 11:11 |
2016-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|