|
278991
|
5.3 |
MEDIUM
Network
|
soplanning
|
soplanning
|
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL pa…
|
CWE-22
Path Traversal
|
CVE-2014-8676
|
2024-11-21 11:19 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278992
|
7.5 |
HIGH
Network
|
soplanning
|
soplanning
|
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force at…
|
CWE-200
Information Exposure
|
CVE-2014-8675
|
2024-11-21 11:19 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278993
|
7.8 |
HIGH
Local
|
avm
|
fritz\!box_6810_lte_firmware fritz\!box_6840_lte_firmware
|
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.
|
CWE-94
Code Injection
|
CVE-2014-8872
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278994
|
7.8 |
HIGH
Local
|
corel
|
coreldraw_photo_paint coreldraw paint_shop_pro painter pdf_fusion
|
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2014-8393
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278995
|
8.8 |
HIGH
Network
|
ibm
|
urbancode_deploy
|
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
|
CWE-352
Origin Validation Error
|
CVE-2014-8900
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278996
|
7.5 |
HIGH
Network
|
sap
|
hybris
|
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5…
|
CWE-22
Path Traversal
|
CVE-2014-8871
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278997
|
6.1 |
MEDIUM
Network
|
cit-e-net
|
cit-e-access
|
Multiple cross-site scripting (XSS) vulnerabilities in Cit-e-Net Cit-e-Access 6.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8753
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278998
|
9.8 |
CRITICAL
Network
|
barracuda
|
load_balancer
|
Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8428
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278999
|
9.8 |
CRITICAL
Network
|
barracuda
|
load_balancer
|
Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2014-8426
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279000
|
8.8 |
HIGH
Network
|
ibm
|
curam_social_program_management
|
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.
|
CWE-77
Command Injection
|
CVE-2014-8903
|
2024-11-21 11:19 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|