|
279471
|
- |
|
linux suse opensuse redhat debian canonical
|
linux_kernel linux_enterprise_server linux_enterprise_real_time_extension linux_enterprise_desktop linux_enterprise_workstation_extension opensuse linux_enterprise_software_developm…
|
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite pr…
|
CWE-20
Improper Input Validation
|
CVE-2014-8160
|
2024-11-21 11:18 |
2015-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279472
|
- |
|
google
|
play_services_sdk
|
The GoogleAuthUtil.getToken method in the Google Play services SDK before 2015 sets parameters in OAuth token requests upon finding a corresponding _opt_ parameter in the Bundle extras argument, whic…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7922
|
2024-11-21 11:18 |
2015-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279473
|
- |
|
redhat
|
kie_workbench
|
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspeci…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8115
|
2024-11-21 11:18 |
2015-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279474
|
- |
|
redhat
|
uberfire
|
The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted content to FileUploadServlet or (2) read arbitrary file…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8114
|
2024-11-21 11:18 |
2015-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279475
|
- |
|
powerpc-utils_project
|
powerpc-utils
|
scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2014-8165
|
2024-11-21 11:18 |
2015-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279476
|
- |
|
cisco
|
adaptive_security_appliance_software
|
Cisco Adaptive Security Appliance (ASA) Software 9.2(.3) and earlier, when challenge-response authentication is used, does not properly select tunnel groups, which allows remote authenticated users t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8023
|
2024-11-21 11:18 |
2015-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279477
|
- |
|
hp
|
universal_configuration_management_database
|
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.
|
CWE-200
Information Exposure
|
CVE-2014-7883
|
2024-11-21 11:18 |
2015-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279478
|
- |
|
redhat
|
jboss_weld
|
Race condition in JBoss Weld before 2.2.8 and 3.x before 3.0.0 Alpha3 allows remote attackers to obtain information from a previous conversation via vectors related to a stale thread state.
|
CWE-362
Race Condition
|
CVE-2014-8122
|
2024-11-21 11:18 |
2015-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279479
|
- |
|
redhat
|
jboss_operations_network jboss_enterprise_application_platform
|
The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to t…
|
CWE-200
Information Exposure
|
CVE-2014-7853
|
2024-11-21 11:18 |
2015-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279480
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authentic…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7849
|
2024-11-21 11:18 |
2015-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|