|
286161
|
8.8 |
HIGH
Network
|
csrf-magic_project
|
csrf-magic
|
In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatica…
|
CWE-352
Origin Validation Error
|
CVE-2013-7464
|
2024-11-21 11:01 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286162
|
5.5 |
MEDIUM
Local
|
check_mk_project
|
check_mk
|
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
|
CWE-59
Link Following
|
CVE-2014-0243
|
2024-11-21 11:01 |
2018-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286163
|
8.8 |
HIGH
Network
|
uclouvain opensuse
|
openjpeg opensuse
|
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impa…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0158
|
2024-11-21 11:01 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286164
|
5.4 |
MEDIUM
Network
|
emberjs
|
ember.js
|
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leverag…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0014
|
2024-11-21 11:01 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286165
|
5.4 |
MEDIUM
Network
|
emberjs
|
ember.js
|
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leverag…
|
CWE-79
Cross-site Scripting
|
CVE-2014-0013
|
2024-11-21 11:01 |
2018-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286166
|
8.8 |
HIGH
Network
|
redhat
|
cloudforms_management_engine
|
The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authoriz…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0087
|
2024-11-21 11:01 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286167
|
9.8 |
CRITICAL
Network
|
hawt redhat
|
hawtio jboss_fuse
|
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
|
CWE-287
Improper Authentication
|
CVE-2014-0121
|
2024-11-21 11:01 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286168
|
8.8 |
HIGH
Network
|
hawt redhat
|
hawtio jboss_fuse
|
Cross-site request forgery (CSRF) vulnerability in the admin terminal in Hawt.io allows remote attackers to hijack the authentication of arbitrary users for requests that run commands on the Karaf se…
|
CWE-352
Origin Validation Error
|
CVE-2014-0120
|
2024-11-21 11:01 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286169
|
5.5 |
MEDIUM
Local
|
apache
|
karaf
|
Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high port…
|
CWE-20
Improper Input Validation
|
CVE-2014-0219
|
2024-11-21 11:01 |
2017-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286170
|
9.8 |
CRITICAL
Network
|
apache
|
cordova_in-app-browser cordova
|
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 throug…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0073
|
2024-11-21 11:01 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|