258721
|
- |
|
apple
|
mac_os_x
|
Finder in Apple OS X before 10.9.2 does not ensure ACL integrity after the viewing of file ACL information, which allows local users to bypass intended access restrictions in opportunistic circumstan…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1264
|
2014-03-11 02:32 |
2014-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258722
|
- |
|
google
|
android
|
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary me…
|
CWE-20
Improper Input Validation
|
CVE-2013-4710
|
2014-03-11 02:25 |
2014-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258723
|
- |
|
atlassian
|
jira
|
Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2014-2313
|
2014-03-11 01:38 |
2014-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258724
|
- |
|
atlassian
|
jira
|
Per: https://confluence.atlassian.com/display/JIRA/JIRA+Security+Advisory+2014-02-26
"Issue 2: Path traversal in JIRA Importers plugin (Windows only)"
|
CWE-22
Path Traversal
|
CVE-2014-2313
|
2014-03-11 01:38 |
2014-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258725
|
- |
|
opendocman
|
opendocman
|
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these details are obtained f…
|
CWE-89
SQL Injection
|
CVE-2014-2317
|
2014-03-11 01:25 |
2014-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258726
|
- |
|
opendocman
|
opendocman
|
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter.
|
CWE-89
SQL Injection
|
CVE-2014-1945
|
2014-03-11 01:24 |
2014-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258727
|
- |
|
owncloud
|
owncloud
|
SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x before 4.5.11 and 5.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vector…
|
CWE-89
SQL Injection
|
CVE-2013-2046
|
2014-03-10 23:15 |
2014-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258728
|
- |
|
owncloud
|
owncloud
|
SQL injection vulnerability in lib/db.php in ownCloud Server 5.0.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-2045
|
2014-03-10 23:12 |
2014-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258729
|
- |
|
openstack
|
image_registry_and_delivery_service_\(glance\)
|
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARN…
|
CWE-255
Credentials Management
|
CVE-2014-1948
|
2014-03-8 14:13 |
2014-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258730
|
- |
|
php
|
php
|
ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in place of a numeric …
|
CWE-189
Numeric Errors
|
CVE-2014-2020
|
2014-03-8 14:13 |
2014-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|