258021
|
- |
|
sap
|
netweaver
|
SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2014-3787
|
2014-05-20 21:43 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258022
|
- |
|
livezilla
|
livezilla
|
LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which allows remote attackers to obtain sensitive…
|
CWE-310
Cryptographic Issues
|
CVE-2013-7385
|
2014-05-20 21:08 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258023
|
- |
|
livezilla
|
livezilla
|
LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might allow remote attackers to obtain sensitive information and…
|
CWE-310
Cryptographic Issues
|
CVE-2013-7033
|
2014-05-20 21:03 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258024
|
- |
|
openvas
|
openvas_administrator
|
OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP commands via a crafted OAP request for version inform…
|
CWE-287
Improper Authentication
|
CVE-2013-6766
|
2014-05-20 20:37 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258025
|
- |
|
vicidial
|
vicidial
|
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQ…
|
CWE-89
SQL Injection
|
CVE-2013-4467
|
2014-05-20 13:06 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258026
|
- |
|
netweblogic
|
events_manager events_manager_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1407
|
2014-05-20 13:00 |
2014-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258027
|
- |
|
unrealircd
|
unrealircd
|
UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors, related to SSL. NOTE: this issue was SPLIT from C…
|
NVD-CWE-Other
|
CVE-2013-7384
|
2014-05-20 04:23 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258028
|
- |
|
unrealircd
|
unrealircd
|
Per: http://cwe.mitre.org/data/definitions/476.html
"CWE-476: NULL Pointer Dereference"
|
NVD-CWE-Other
|
CVE-2013-7384
|
2014-05-20 04:23 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258029
|
- |
|
opentext
|
exceed_ondemand
|
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.
|
CWE-310
Cryptographic Issues
|
CVE-2013-6994
|
2014-05-20 04:21 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258030
|
- |
|
opentext
|
exceed_ondemand
|
The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obta…
|
CWE-310
Cryptographic Issues
|
CVE-2013-6807
|
2014-05-20 04:16 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|