257751
|
- |
|
ibm
|
storwize_unified_v7000_software storwize_unified_v7000
|
IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by leveraging access to the service account.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3043
|
2014-07-24 03:49 |
2014-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257752
|
- |
|
advantech
|
advantech_webaccess
|
The BrowseFolder method in the bwocxrun ActiveX control in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.
|
CWE-200
Information Exposure
|
CVE-2014-2368
|
2014-07-24 03:48 |
2014-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257753
|
- |
|
advantech
|
advantech_webaccess
|
The ChkCookie subroutine in an ActiveX control in broadweb/include/gChkCook.asp in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a crafted call.
|
CWE-200
Information Exposure
|
CVE-2014-2367
|
2014-07-24 03:47 |
2014-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257754
|
- |
|
advantech
|
advantech_webaccess
|
upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading HTML source code.
|
CWE-200
Information Exposure
|
CVE-2014-2366
|
2014-07-24 03:46 |
2014-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257755
|
- |
|
sgminer_project cgminer_project
|
sgminer cgminer
|
The parse_notify function in util.c in sgminer before 4.2.2 and cgminer 3.3.0 through 4.0.1 allows man-in-the-middle attackers to cause a denial of service (application exit) via a crafted (1) bbvers…
|
CWE-20
Improper Input Validation
|
CVE-2014-4503
|
2014-07-24 03:25 |
2014-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257756
|
- |
|
sgminer_project cgminer_project bfgminer
|
sgminer cgminer bfgminer
|
Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnec…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4501
|
2014-07-24 03:07 |
2014-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257757
|
- |
|
cybozu
|
garoon
|
Cross-site scripting (XSS) vulnerability in the Map search functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspe…
|
CWE-79
Cross-site Scripting
|
CVE-2014-1995
|
2014-07-24 02:40 |
2014-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257758
|
- |
|
advantech
|
advantech_webaccess
|
Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2014-2365
|
2014-07-24 02:39 |
2014-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257759
|
- |
|
autodesk
|
sketchbook_pro
|
Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmap data in a PXD file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-3939
|
2014-07-24 02:19 |
2014-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257760
|
- |
|
autodesk
|
sketchbook_pro
|
Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based buffer overflow.
|
CWE-189
Numeric Errors
|
CVE-2014-3938
|
2014-07-24 02:14 |
2014-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|