258161
|
- |
|
ayatana_project
|
unity
|
Unity before 7.2.1 does not properly handle entry activation, which allows physically proximate attackers to bypass the lock screen by holding the ENTER key, which triggers the process to crash.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3202
|
2014-05-7 22:43 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258162
|
- |
|
skyphe
|
file-gallery
|
The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting field…
|
CWE-94
Code Injection
|
CVE-2014-2558
|
2014-05-7 22:23 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258163
|
- |
|
mongodb
|
mongodb
|
The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON obj…
|
CWE-20
Improper Input Validation
|
CVE-2012-6619
|
2014-05-7 12:45 |
2014-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258164
|
- |
|
nagios
|
plugins
|
The IPXPING_COMMAND in contrib/check_ipxping.c in Nagios Plugins 1.4.16 allows local users to gain privileges via a symlink attack on /tmp/ipxping/ipxping.
|
CWE-59
Link Following
|
CVE-2013-4215
|
2014-05-7 04:10 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258165
|
- |
|
redhat
|
jboss_web_framework_kit
|
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.
|
CWE-79
Cross-site Scripting
|
CVE-2014-0149
|
2014-05-7 04:07 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258166
|
- |
|
amtelco
|
misecuremessages
|
Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2347
|
2014-05-6 22:16 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258167
|
- |
|
david_leonard
|
pkstat
|
tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
|
CWE-59
Link Following
|
CVE-2013-0350
|
2014-05-6 02:27 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258168
|
- |
|
randall_hand fedoraproject
|
yerase\'s_tnef_stream_reader fedora
|
Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of service (crash) via a crafted TNEF file, which triggers a buffer …
|
CWE-189
Numeric Errors
|
CVE-2010-5109
|
2014-05-6 02:19 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258169
|
- |
|
conceptronic
|
c54apm_firmware c54apm
|
CRLF injection vulnerability in goform/formWlSiteSurvey on the Conceptronic C54APM access point with runtime code 1.26 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP respon…
|
CWE-20
Improper Input Validation
|
CVE-2014-1406
|
2014-05-6 00:29 |
2014-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258170
|
- |
|
conceptronic
|
c54apm_firmware c54apm
|
The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via an HTTP request, as …
|
CWE-255
Credentials Management
|
CVE-2014-1408
|
2014-05-6 00:28 |
2014-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|