|
283541
|
- |
|
vtiger
|
vtiger_crm
|
modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPa…
|
CWE-20
Improper Input Validation
|
CVE-2014-2269
|
2024-11-21 11:05 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283542
|
- |
|
cisco
|
cns_network_registrar
|
The DHCPv6 server module in Cisco CNS Network Registrar 7.1 allows remote attackers to cause a denial of service (daemon reload) via a malformed DHCPv6 packet, aka Bug ID CSCuo07437.
|
CWE-20
Improper Input Validation
|
CVE-2014-2155
|
2024-11-21 11:05 |
2014-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283543
|
- |
|
toshibatec
|
e-studio-282 e-studio-283 e-studio-232 e-studio-233
|
Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Studio 232, 233, 282, and 283 devices allows remote attackers to hijack the authen…
|
CWE-352
Origin Validation Error
|
CVE-2014-1990
|
2024-11-21 11:05 |
2014-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283544
|
- |
|
cybozu
|
remote_service_manager
|
Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2014-1984
|
2024-11-21 11:05 |
2014-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283545
|
- |
|
cybozu
|
remote_service_manager
|
Unspecified vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers to cause a denial of service (CPU consumption) via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2014-1983
|
2024-11-21 11:05 |
2014-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283546
|
- |
|
lyesoft
|
andexplorer
|
Directory traversal vulnerability in the LYSESOFT AndExplorer application before 20140403 and AndExplorerPro application before 20140405 for Android allows attackers to overwrite or create arbitrary …
|
CWE-22
Path Traversal
|
CVE-2014-1974
|
2024-11-21 11:05 |
2014-04-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283547
|
- |
|
imapsync_project
|
imapsync
|
imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing t…
|
CWE-255
Credentials Management
|
CVE-2014-2014
|
2024-11-21 11:05 |
2014-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283548
|
- |
|
python pythonware
|
pillow python_imaging_library
|
The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1933
|
2024-11-21 11:05 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283549
|
- |
|
python pythonware
|
pillow python_imaging_library
|
The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (…
|
CWE-59
Link Following
|
CVE-2014-1932
|
2024-11-21 11:05 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283550
|
- |
|
kokuyo
|
camiapp
|
The Content Provider in the KOKUYO CamiApp application 1.21.1 and earlier for Android allows attackers to bypass intended access restrictions and read database information via a crafted application.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1986
|
2024-11-21 11:05 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|