|
283681
|
- |
|
google
|
chrome
|
The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an attach operation, which allows remote attack…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3172
|
2024-11-21 11:07 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283682
|
- |
|
google
|
chrome
|
Use-after-free vulnerability in the V8 bindings in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact …
|
NVD-CWE-Other
|
CVE-2014-3171
|
2024-11-21 11:07 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283683
|
- |
|
google
|
chrome
|
extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote attackers to spoof the extension permission dialog b…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3170
|
2024-11-21 11:07 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283684
|
- |
|
opensuse debian google
|
opensuse debian_linux chrome
|
Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or po…
|
NVD-CWE-Other
|
CVE-2014-3169
|
2024-11-21 11:07 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283685
|
- |
|
google opensuse debian
|
chrome opensuse debian_linux
|
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other …
|
NVD-CWE-Other
|
CVE-2014-3168
|
2024-11-21 11:07 |
2014-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283686
|
- |
|
ibm
|
emptoris_spend_analysis
|
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authe…
|
CWE-352
Origin Validation Error
|
CVE-2014-3061
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283687
|
- |
|
ibm
|
emptoris_contract_management
|
SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows re…
|
CWE-89
SQL Injection
|
CVE-2014-3041
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283688
|
- |
|
ibm
|
emptoris_spend_analysis
|
Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3035
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283689
|
- |
|
ibm
|
emptoris_contract_management
|
Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFi…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3034
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283690
|
- |
|
cisco
|
ios_xr asr_9000_rsp440_router asr_9001 asr_9006 asr_9010 asr_9904 asr_9912 asr_9922
|
Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of…
|
CWE-20
Improper Input Validation
|
CVE-2014-3335
|
2024-11-21 11:07 |
2014-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|