|
279651
|
- |
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8960
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279652
|
- |
|
opensuse phpmyadmin
|
opensuse phpmyadmin
|
Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allows remote authentica…
|
CWE-22
Path Traversal
|
CVE-2014-8959
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279653
|
- |
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8958
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279654
|
- |
|
adobe
|
acrobat_reader acrobat
|
Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently write to file…
|
CWE-362
Race Condition
|
CVE-2014-9150
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279655
|
- |
|
linux
|
linux_kernel
|
The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel through 3.17.4 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local …
|
CWE-17
Code
|
CVE-2014-9090
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279656
|
- |
|
linux
|
linux_kernel
|
The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by l…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8989
|
2024-11-21 11:20 |
2014-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279657
|
- |
|
debian mantisbt
|
debian_linux mantisbt
|
Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_se…
|
CWE-89
SQL Injection
|
CVE-2014-9089
|
2024-11-21 11:20 |
2014-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279658
|
- |
|
check_diskio_project
|
check_diskio
|
The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_statu…
|
CWE-18
Source Code
|
CVE-2014-8994
|
2024-11-21 11:20 |
2014-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279659
|
- |
|
openvpn
|
openvpn_access_server
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of a…
|
CWE-352
Origin Validation Error
|
CVE-2014-9104
|
2024-11-21 11:20 |
2014-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279660
|
- |
|
kunena
|
kunena
|
Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) index value of an array …
|
CWE-79
Cross-site Scripting
|
CVE-2014-9103
|
2024-11-21 11:20 |
2014-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|