258141
|
- |
|
xangati
|
xangati_software_release xangati_xnr
|
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the file parameter in a getUpgradeStatu…
|
CWE-22
Path Traversal
|
CVE-2014-0358
|
2014-04-16 04:07 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258142
|
- |
|
zyxel
|
n300_netusb_nbg-419n_firmware n300_netusb_nbg-419n
|
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 has a hardcoded password of qweasdzxc for an unspecified account, which allows remote attackers to obtain index.asp login ac…
|
CWE-255
Credentials Management
|
CVE-2014-0354
|
2014-04-16 02:56 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258143
|
- |
|
zyxel
|
n300_netusb_nbg-419n_firmware n300_netusb_nbg-419n
|
Multiple stack-based buffer overflows on the ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allow man-in-the-middle attackers to execute arbitrary code via (1) a long temp att…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0355
|
2014-04-16 02:56 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258144
|
- |
|
zyxel
|
n300_netusb_nbg-419n_firmware n300_netusb_nbg-419n
|
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to execute arbitrary code via shell metacharacters in input to the (1) detectWeather, (2) set_langua…
|
CWE-78
OS Command
|
CVE-2014-0356
|
2014-04-16 02:56 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258145
|
- |
|
zyxel
|
n300_netusb_nbg-419n_firmware n300_netusb_nbg-419n
|
The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to bypass authentication by using %2F sequences in place of / (slash) characters.
|
CWE-287
Improper Authentication
|
CVE-2014-0353
|
2014-04-16 02:55 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258146
|
- |
|
ontariosystems
|
artiva_architect artiva_healthcare artiva_rm artiva_workstation
|
The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option…
|
CWE-287
Improper Authentication
|
CVE-2014-0348
|
2014-04-16 01:57 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258147
|
- |
|
pivotx
|
pivotx
|
Multiple unrestricted file upload vulnerabilities in fileupload.php in PivotX before 2.3.9 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .php or (2) .p…
|
NVD-CWE-Other
|
CVE-2014-0342
|
2014-04-16 01:39 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258148
|
- |
|
pivotx
|
pivotx
|
Per: http://cwe.mitre.org/data/definitions/434.html
"CWE-434: Unrestricted Upload of File with Dangerous Type"
|
NVD-CWE-Other
|
CVE-2014-0342
|
2014-04-16 01:39 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258149
|
- |
|
openafs
|
openafs
|
OpenAFS before 1.6.7 delays the listen thread when an RXS_CheckResponse fails, which allows remote attackers to cause a denial of service (performance degradation) via an invalid packet.
|
CWE-20
Improper Input Validation
|
CVE-2014-2852
|
2014-04-15 23:35 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258150
|
- |
|
juniper
|
junos
|
The Enhanced Web Filtering (EWF) in Juniper Junos before 10.4R15, 11.4 before 11.4R9, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D10, and 12.1X46 before 12.1X46-D10, as us…
|
CWE-20
Improper Input Validation
|
CVE-2014-2714
|
2014-04-15 23:06 |
2014-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|