|
283521
|
6.1 |
MEDIUM
Network
|
infoware
|
mapsuite
|
Cross-site scripting (XSS) vulnerability in infoware MapSuite MapAPI 1.0.x before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-2843
|
2024-11-21 11:07 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283522
|
5.9 |
MEDIUM
Network
|
lwp\
|
\
|
The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS…
|
CWE-295
Improper Certificate Validation
|
CVE-2014-3230
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283523
|
9.8 |
CRITICAL
Network
|
fishshell
|
fish
|
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as d…
|
CWE-20
Improper Input Validation
|
CVE-2014-2914
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283524
|
7.0 |
HIGH
Local
|
fishshell
|
fish
|
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable…
|
CWE-362
Race Condition
|
CVE-2014-2906
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283525
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2898
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283526
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote attackers to have unspecified impact via a crafted HMA…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2897
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283527
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an o…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2896
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283528
|
7.5 |
HIGH
Network
|
publify_project
|
publify
|
Publify before 8.0.1 is vulnerable to a Denial of Service attack
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2014-3211
|
2024-11-21 11:07 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283529
|
8.8 |
HIGH
Network
|
dlink
|
dwr-113_firmware
|
Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that chang…
|
CWE-352
Origin Validation Error
|
CVE-2014-3136
|
2024-11-21 11:07 |
2019-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283530
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
|
CWE-287
Improper Authentication
|
CVE-2014-2904
|
2024-11-21 11:07 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|