258441
|
- |
|
vmware
|
vsphere_client
|
VMware vSphere Client 4.0, 4.1, 5.0 before Update 3, and 5.1 before Update 2 does not properly validate updates to Client files, which allows remote attackers to trigger the downloading and execution…
|
CWE-20
Improper Input Validation
|
CVE-2014-1209
|
2014-04-15 01:51 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258442
|
- |
|
apps4u\@android
|
sd_card_manager
|
Directory traversal vulnerability in the apps4u@android SD Card Manager application before 20140224 for Android allows attackers to overwrite or create arbitrary files via a crafted filename.
|
CWE-22
Path Traversal
|
CVE-2014-1969
|
2014-04-15 01:26 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258443
|
- |
|
ioserver
|
ioserver_opc_server opc_drivers
|
The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafte…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-0777
|
2014-04-15 01:19 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258444
|
- |
|
sophos
|
web_appliance_firmware web_appliance
|
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2849
|
2014-04-15 00:38 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258445
|
- |
|
sophos
|
web_appliance_firmware web_appliance
|
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address paramet…
|
CWE-78
OS Command
|
CVE-2014-2850
|
2014-04-15 00:38 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258446
|
- |
|
tenable
|
nessus plugin-set
|
A race condition in the wmi_malware_scan.nbin plugin before 201402262215 for Nessus 5.2.1 allows local users to gain privileges by replacing the dissolvable agent executable in the Windows temp direc…
|
CWE-362
Race Condition
|
CVE-2014-2848
|
2014-04-15 00:21 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258447
|
- |
|
construtiva
|
cis_manager_cms
|
SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands via the TroncoID parameter.
|
CWE-89
SQL Injection
|
CVE-2014-2847
|
2014-04-15 00:15 |
2014-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258448
|
- |
|
snilesh
|
content_slide
|
Cross-site request forgery (CSRF) vulnerability in the Content Slide plugin 1.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin …
|
CWE-352
Origin Validation Error
|
CVE-2013-2708
|
2014-04-14 21:52 |
2014-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258449
|
- |
|
rodrigo_polo
|
stream_video_player
|
Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change p…
|
CWE-352
Origin Validation Error
|
CVE-2013-2706
|
2014-04-14 20:13 |
2014-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258450
|
- |
|
isode
|
m-link
|
Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP s…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2742
|
2014-04-12 04:49 |
2014-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|