258301
|
- |
|
ruckuswireless
|
zoneflex_2942__firmware zoneflex_2942
|
Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and subsequently access certain configuration/ and maintenance/ scripts, by constructi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5030
|
2014-04-23 23:26 |
2013-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258302
|
- |
|
cisco
|
ios
|
The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-1317
|
2014-04-23 23:21 |
2014-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258303
|
- |
|
cisco
|
ios
|
Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.
|
CWE-399
Resource Management Errors
|
CVE-2012-0360
|
2014-04-23 23:18 |
2014-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258304
|
- |
|
siege
|
phpmyid
|
Cross-site scripting (XSS) vulnerability in the wrap_html function in MyID.php in phpMyID 0.9 allows remote attackers to inject arbitrary web script or HTML via the openid_error parameter to MyID.con…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2890
|
2014-04-23 22:37 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258305
|
- |
|
carbonblack
|
carbon_black
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative …
|
CWE-352
Origin Validation Error
|
CVE-2014-1615
|
2014-04-23 21:36 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258306
|
- |
|
freedesktop
|
poppler
|
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on tem…
|
CWE-59
Link Following
|
CVE-2013-4472
|
2014-04-23 21:20 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258307
|
- |
|
vtiger
|
vtiger_crm
|
modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPa…
|
CWE-20
Improper Input Validation
|
CVE-2014-2269
|
2014-04-23 01:31 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258308
|
- |
|
eduserv
|
openathens_service_provider
|
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."
|
CWE-287
Improper Authentication
|
CVE-2012-5353
|
2014-04-23 01:29 |
2012-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258309
|
- |
|
fitnesse
|
fitnesse_wiki
|
FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.
|
NVD-CWE-Other
|
CVE-2014-1216
|
2014-04-23 01:24 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258310
|
- |
|
fitnesse
|
fitnesse_wiki
|
Per: https://cwe.mitre.org/data/definitions/77.html
"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')"
|
NVD-CWE-Other
|
CVE-2014-1216
|
2014-04-23 01:24 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|