|
279411
|
6.5 |
MEDIUM
Network
|
redhat
|
satellite
|
Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
|
CWE-22
Path Traversal
|
CVE-2014-8163
|
2024-11-21 11:18 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279412
|
6.1 |
MEDIUM
Local
|
redhat
|
satellite
|
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
|
CWE-284
Improper Access Control
|
CVE-2014-8168
|
2024-11-21 11:18 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279413
|
5.3 |
MEDIUM
Network
|
d-link
|
dns-327l_firmware dns-320l_firmware
|
The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which allows remote attackers to obtain arbitrary photos…
|
CWE-287 CWE-200
Improper Authentication Information Exposure
|
CVE-2014-7860
|
2024-11-21 11:18 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279414
|
9.8 |
CRITICAL
Network
|
d-link
|
dns-322l_firmware dns-320lw_firmware dnr-326_firmware dns-327l_firmware dnr-320l_firmware
|
Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-326 before 2.10 build 03, and DNS-327L before 1.04b01 allows …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-7859
|
2024-11-21 11:18 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279415
|
9.8 |
CRITICAL
Network
|
d-link
|
dnr-326_firmware
|
The check_login function in D-Link DNR-326 before 2.10 build 03 allows remote attackers to bypass authentication and log in by setting the username cookie parameter to an arbitrary string.
|
CWE-287
Improper Authentication
|
CVE-2014-7858
|
2024-11-21 11:18 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279416
|
9.8 |
CRITICAL
Network
|
d-link
|
dns-322l_firmware dns-325_firmware dns-345_firmware dns-320b_firmware dnr-326_firmware dns-327l_firmware dns-320l_firmware
|
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass …
|
CWE-287
Improper Authentication
|
CVE-2014-7857
|
2024-11-21 11:18 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279417
|
4.6 |
MEDIUM
Physics
|
google
|
android
|
Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4.4 allows physically proximate attackers with a direct connection to the target…
|
CWE-22
Path Traversal
|
CVE-2014-7954
|
2024-11-21 11:18 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279418
|
7.0 |
HIGH
Local
|
google
|
android
|
Race condition in the bindBackupAgent method in the ActivityManagerService in Android 4.4.4 allows local users with adb shell access to execute arbitrary code or any valid package as system by runnin…
|
CWE-362
Race Condition
|
CVE-2014-7953
|
2024-11-21 11:18 |
2017-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279419
|
8.8 |
HIGH
Network
|
opendaylight
|
defense4all
|
OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.
|
CWE-20
Improper Input Validation
|
CVE-2014-8149
|
2024-11-21 11:18 |
2017-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279420
|
6.5 |
MEDIUM
Network
|
libtiff opensuse
|
libtiff opensuse
|
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, …
|
CWE-125
Out-of-bounds Read
|
CVE-2014-8127
|
2024-11-21 11:18 |
2017-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|