|
280941
|
- |
|
manageengine
|
device_expert
|
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.
|
CWE-200
Information Exposure
|
CVE-2014-5377
|
2024-11-21 11:11 |
2014-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280942
|
- |
|
plack_project
|
plack
|
Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a c…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5269
|
2024-11-21 11:11 |
2014-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280943
|
- |
|
tibco
|
spotfire_server
|
Unspecified vulnerability in the Authentication Module in TIBCO Spotfire Server before 4.5.2, 5.0.x before 5.0.3, 5.5.x before 5.5.2, 6.0.x before 6.0.3, and 6.5.x before 6.5.1 allows remote attacker…
|
NVD-CWE-noinfo
|
CVE-2014-5285
|
2024-11-21 11:11 |
2014-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280944
|
- |
|
check_mk_project
|
check_mk
|
The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object,…
|
CWE-94
Code Injection
|
CVE-2014-5340
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280945
|
- |
|
check_mk_project
|
check_mk
|
Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk files) to arbitrary locations via vectors related to row selections.
|
NVD-CWE-noinfo
|
CVE-2014-5339
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280946
|
- |
|
iii
|
sierra
|
Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate ac…
|
CWE-200
Information Exposure
|
CVE-2014-5137
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280947
|
- |
|
iii
|
sierra
|
Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5136
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280948
|
- |
|
labanquepostale
|
labanquepostale
|
The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banki…
|
CWE-200
Information Exposure
|
CVE-2014-5076
|
2024-11-21 11:11 |
2014-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280949
|
- |
|
spi-inc
|
ganeti
|
The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5247
|
2024-11-21 11:11 |
2014-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280950
|
- |
|
xen
|
xen
|
Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5147
|
2024-11-21 11:11 |
2014-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|