258431
|
- |
|
advantech
|
advantech_webaccess
|
The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to execute (1) setup.exe, (2) bwvbprt.exe, and (3) bw…
|
NVD-CWE-Other
|
CVE-2014-0773
|
2014-04-15 02:56 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258432
|
- |
|
advantech
|
advantech_webaccess
|
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
|
NVD-CWE-Other
|
CVE-2014-0773
|
2014-04-15 02:56 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258433
|
- |
|
j2k-codec
|
j2k-codec
|
Multiple unspecified vulnerabilities in J2k-Codec allow remote attackers to execute arbitrary code via a crafted JPEG 2000 file.
|
NVD-CWE-noinfo
|
CVE-2014-0349
|
2014-04-15 02:47 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258434
|
- |
|
advantech
|
advantech_webaccess
|
The OpenUrlToBufferTimeout method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL.
|
CWE-200
Information Exposure
|
CVE-2014-0772
|
2014-04-15 02:44 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258435
|
- |
|
advantech
|
advantech_webaccess
|
The OpenUrlToBuffer method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL.
|
CWE-200
Information Exposure
|
CVE-2014-0771
|
2014-04-15 02:42 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258436
|
- |
|
advantech
|
advantech_webaccess
|
Stack-based buffer overflow in Advantech WebAccess before 7.2 allows remote attackers to execute arbitrary code via a long UserName parameter.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0770
|
2014-04-15 02:40 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258437
|
- |
|
websense
|
triton_unified_security_center triton_web_filter triton_web_security triton_web_security_gateway triton_web_security_gateway_anywhere
|
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter 7.7.3 before Hotfix 31, Web Security 7.7.3 before Hotfix 31, Web Security Gateway 7.7.3 before Hotfix…
|
CWE-255
Credentials Management
|
CVE-2014-0347
|
2014-04-15 02:39 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258438
|
- |
|
osisoft
|
pi_interface
|
The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows physically proximate attackers to cause a denial of service (interface shutdown) via crafted input over a serial line.
|
CWE-20
Improper Input Validation
|
CVE-2013-2828
|
2014-04-15 02:19 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258439
|
- |
|
osisoft
|
pi_interface
|
The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows remote attackers to cause a denial of service (interface shutdown) via a crafted TCP packet.
|
CWE-20
Improper Input Validation
|
CVE-2013-2809
|
2014-04-15 02:13 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258440
|
- |
|
vmware
|
vsphere_client
|
VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificat…
|
CWE-310
Cryptographic Issues
|
CVE-2014-1210
|
2014-04-15 01:58 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|