|
280301
|
5.3 |
MEDIUM
Network
|
netsweeper
|
netsweeper
|
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the quarantine via the ip parameter to webadmin/user…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9610
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280302
|
5.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sen…
|
CWE-254
7PK - Security Features
|
CVE-2014-9635
|
2024-11-21 11:21 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280303
|
5.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmissi…
|
CWE-254
7PK - Security Features
|
CVE-2014-9634
|
2024-11-21 11:21 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280304
|
7.5 |
HIGH
Network
|
mantisbt
|
mantisbt
|
CAPTCHA bypass vulnerability in MantisBT before 1.2.19.
|
CWE-287
Improper Authentication
|
CVE-2014-9624
|
2024-11-21 11:21 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280305
|
8.8 |
HIGH
Network
|
ibm
|
ib6131_firmware en6131_firmware
|
Cross-site request forgery (CSRF) vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware 3.4.0000 and earlier.
|
CWE-352
Origin Validation Error
|
CVE-2014-9565
|
2024-11-21 11:21 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280306
|
7.5 |
HIGH
Network
|
mpg123
|
mpg123
|
Buffer overflow in mpg123 before 1.18.0.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9497
|
2024-11-21 11:21 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280307
|
9.8 |
CRITICAL
Network
|
smartcms
|
smartcms
|
Multiple SQL injection vulnerabilities in SmartCMS v.2.
|
CWE-89
SQL Injection
|
CVE-2014-9558
|
2024-11-21 11:21 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280308
|
6.1 |
MEDIUM
Network
|
smartwebsites
|
smartcms
|
Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9557
|
2024-11-21 11:21 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280309
|
6.1 |
MEDIUM
Network
|
bmc
|
footprints_service_core
|
Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9514
|
2024-11-21 11:21 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280310
|
9.8 |
CRITICAL
Network
|
debian
|
xbindkeys-config
|
Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.
|
CWE-284
Improper Access Control
|
CVE-2014-9513
|
2024-11-21 11:21 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|