|
279231
|
- |
|
fluxbb
|
fluxbb
|
Directory traversal vulnerability in install.php in FluxBB before 1.5.8 allows remote attackers to include and execute arbitrary local install.php files via a .. (dot dot) in the install_lang paramet…
|
CWE-22
Path Traversal
|
CVE-2014-9574
|
2024-11-21 11:21 |
2015-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279232
|
- |
|
voxpupuli
|
rabbitmq
|
puppetlabs-rabbitmq 3.0 through 4.1 stores the RabbitMQ Erlang cookie value in the facts of a node, which allows local users to obtain sensitive information as demonstrated by using Facter.
|
CWE-200
Information Exposure
|
CVE-2014-9568
|
2024-11-21 11:21 |
2015-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279233
|
- |
|
snipsnap
|
snipsnap
|
Cross-site scripting (XSS) vulnerability in SnipSnap 0.5.2a, 1.0b1, and 1.0b2 allows remote attackers to inject arbitrary web script or HTML via the query parameter to /snipsnap-search.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9559
|
2024-11-21 11:21 |
2015-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279234
|
- |
|
libmspack_project
|
libmspack
|
Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file, which triggers an infinite loop.
|
CWE-189
Numeric Errors
|
CVE-2014-9556
|
2024-11-21 11:21 |
2015-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279235
|
- |
|
vmware
|
rabbitmq
|
CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks…
|
NVD-CWE-Other
|
CVE-2014-9650
|
2024-11-21 11:21 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279236
|
- |
|
vmware
|
rabbitmq
|
Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9649
|
2024-11-21 11:21 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279237
|
- |
|
google
|
chrome
|
components/navigation_interception/intercept_navigation_resource_throttle.cc in Google Chrome before 40.0.2214.91 on Android does not properly restrict use of intent: URLs to open an application afte…
|
CWE-284
Improper Access Control
|
CVE-2014-9648
|
2024-11-21 11:21 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279238
|
- |
|
google
|
chrome
|
Use-after-free vulnerability in PDFium, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF …
|
NVD-CWE-Other
|
CVE-2014-9647
|
2024-11-21 11:21 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279239
|
- |
|
google
|
chrome
|
Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Googl…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9646
|
2024-11-21 11:21 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279240
|
- |
|
mantisbt
|
mantisbt
|
SQL injection vulnerability in manage_user_page.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote administrators with FILE privileges to execute arbitrary SQL commands via the…
|
CWE-89
SQL Injection
|
CVE-2014-9573
|
2024-11-21 11:21 |
2015-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|