258501
|
- |
|
redhat
|
jboss_operations_network
|
Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2011-4573
|
2014-04-1 23:38 |
2014-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258502
|
- |
|
emc
|
vplex_geosynchrony
|
Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2014-0635
|
2014-04-1 23:16 |
2014-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258503
|
- |
|
emc
|
vplex_geosynchrony
|
EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sen…
|
CWE-20
Improper Input Validation
|
CVE-2014-0634
|
2014-04-1 23:14 |
2014-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258504
|
- |
|
emc
|
vplex_geosynchrony
|
The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary code by leveraging an …
|
CWE-20
Improper Input Validation
|
CVE-2014-0633
|
2014-04-1 23:13 |
2014-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258505
|
- |
|
sonatype
|
nexus
|
Unspecified vulnerability in Sonatype Nexus OSS and Pro 2.4.0 through 2.7.1 allows attackers to create arbitrary user accounts via unknown vectors related to "an unauthenticated execution path."
|
NVD-CWE-noinfo
|
CVE-2014-2034
|
2014-04-1 21:55 |
2014-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258506
|
- |
|
jgaa
|
warftpd
|
Unspecified vulnerability in War FTP Daemon (warftpd) 1.82, when running as a Windows service, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unk…
|
NVD-CWE-noinfo
|
CVE-2013-2278
|
2014-04-1 20:13 |
2014-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258507
|
- |
|
jgaa
|
warftpd
|
Format string vulnerability in War FTP Daemon (warftpd) 1.82 RC 12 allows remote authenticated users to cause a denial of service (crash) via format string specifiers in a LIST command.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2009-5141
|
2014-04-1 20:07 |
2014-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258508
|
- |
|
freetype canonical
|
freetype ubuntu_linux
|
The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to c…
|
CWE-20
Improper Input Validation
|
CVE-2014-2241
|
2014-04-1 15:29 |
2014-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258509
|
- |
|
blackberry
|
qnx_neutrino_rtos
|
/sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the ro…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2534
|
2014-04-1 15:29 |
2014-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258510
|
- |
|
intel mcafee
|
expressway_cloud_access_360 cloud_identity_manager cloud_single_sign_on
|
Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows …
|
CWE-22
Path Traversal
|
CVE-2014-2536
|
2014-04-1 15:29 |
2014-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|