|
283141
|
- |
|
apple
|
iphone_os
|
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents direc…
|
CWE-310
Cryptographic Issues
|
CVE-2014-4448
|
2024-11-21 11:10 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283142
|
- |
|
websupporter
|
wp_amasin_-_the_amazon_affiliate_shop
|
Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pat…
|
CWE-22
Path Traversal
|
CVE-2014-4577
|
2024-11-21 11:10 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283143
|
- |
|
cbi_referral_manager_project
|
cbi_referral_manager
|
Cross-site scripting (XSS) vulnerability in getNetworkSites.php in the CBI Referral Manager plugin 1.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via t…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4517
|
2024-11-21 11:10 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283144
|
- |
|
alipay_project
|
alipay
|
Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4514
|
2024-11-21 11:10 |
2014-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283145
|
- |
|
ibm
|
tririga_application_platform
|
IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows remote attackers to execute arbitrary code via a crafted URL.
|
CWE-20
Improper Input Validation
|
CVE-2014-4840
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283146
|
- |
|
ibm
|
tririga_application_platform
|
Cross-site scripting (XSS) vulnerability in GanttProjectSchedulerPopup.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4838
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283147
|
- |
|
ibm
|
tririga_application_platform
|
Cross-site scripting (XSS) vulnerability in NewDocument.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 allows r…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4837
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283148
|
- |
|
ibm
|
tririga_application_platform
|
Cross-site scripting (XSS) vulnerability in breakOutWithName.jsp in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 all…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4836
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283149
|
- |
|
ibm
|
qradar_security_information_and_event_manager
|
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 allows remote authenticated users to gain privileges via invalid input.
|
CWE-20
Improper Input Validation
|
CVE-2014-4833
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283150
|
- |
|
ibm
|
qradar_security_information_and_event_manager
|
IBM Security QRadar SIEM QRM 7.1 MR1 and QRM/QVM 7.2 MR2 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potenti…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4830
|
2024-11-21 11:10 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|