|
279751
|
7.8 |
HIGH
Local
|
corel
|
coreldraw_photo_paint coreldraw paint_shop_pro painter pdf_fusion
|
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2014-8393
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279752
|
8.8 |
HIGH
Network
|
ibm
|
urbancode_deploy
|
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
|
CWE-352
Origin Validation Error
|
CVE-2014-8900
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279753
|
7.5 |
HIGH
Network
|
sap
|
hybris
|
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5…
|
CWE-22
Path Traversal
|
CVE-2014-8871
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279754
|
6.1 |
MEDIUM
Network
|
cit-e-net
|
cit-e-access
|
Multiple cross-site scripting (XSS) vulnerabilities in Cit-e-Net Cit-e-Access 6.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8753
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279755
|
9.8 |
CRITICAL
Network
|
barracuda
|
load_balancer
|
Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8428
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279756
|
9.8 |
CRITICAL
Network
|
barracuda
|
load_balancer
|
Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2014-8426
|
2024-11-21 11:19 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279757
|
8.8 |
HIGH
Network
|
ibm
|
curam_social_program_management
|
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.
|
CWE-77
Command Injection
|
CVE-2014-8903
|
2024-11-21 11:19 |
2017-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279758
|
9.8 |
CRITICAL
Network
|
seagate
|
business_nas_firmware
|
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraging use of a static encryption key to create session token…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2014-8687
|
2024-11-21 11:19 |
2017-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279759
|
6.2 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
The JPEG decoder in ImageMagick before 6.8.9-9 allows local users to cause a denial of service (out-of-bounds memory access and crash).
|
CWE-125
Out-of-bounds Read
|
CVE-2014-8716
|
2024-11-21 11:19 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279760
|
5.5 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
DCM decode in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
|
CWE-125
Out-of-bounds Read
|
CVE-2014-8562
|
2024-11-21 11:19 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|