258771
|
- |
|
ithoughts
|
ithoughtshd
|
The iThoughts web server in the iThoughtsHD app 4.19 for iOS on iPad devices allows remote attackers to cause a denial of service (disk consumption) by uploading a large file.
|
CWE-20
Improper Input Validation
|
CVE-2014-1828
|
2014-03-27 03:18 |
2014-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258772
|
- |
|
ithoughts
|
ithoughtshd
|
The iThoughtsHD app 4.19 for iOS on iPad devices, when the WiFi Transfer feature is used, allows remote attackers to upload arbitrary files by placing a %00 sequence after a dangerous extension, as d…
|
CWE-20
Improper Input Validation
|
CVE-2014-1827
|
2014-03-27 03:14 |
2014-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258773
|
- |
|
ithoughts
|
ithoughtshd
|
Cross-site scripting (XSS) vulnerability in the iThoughtsHD app 4.19 for iOS on iPad devices, when the WiFi Transfer feature is used, allows remote attackers to inject arbitrary web script or HTML vi…
|
CWE-79
Cross-site Scripting
|
CVE-2014-1826
|
2014-03-27 03:11 |
2014-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258774
|
- |
|
virtualaccess
|
gw6110a_firmware gw6110a
|
The web interface on Virtual Access GW6110A routers with software 9.00 before 9.09.27, 9.50 before 9.50.21, and 10.00 before 10.00.21 allows remote authenticated users to gain privileges via a modifi…
|
NVD-CWE-Other
|
CVE-2014-0343
|
2014-03-27 00:48 |
2014-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258775
|
- |
|
virtualaccess
|
gw6110a_firmware gw6110a
|
Per: http://cwe.mitre.org/data/definitions/472.html
"CWE-472: External Control of Assumed-Immutable Web Parameter"
|
NVD-CWE-Other
|
CVE-2014-0343
|
2014-03-27 00:48 |
2014-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258776
|
- |
|
openstack
|
compute
|
The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denia…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2573
|
2014-03-26 22:41 |
2014-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258777
|
- |
|
siemens
|
simatic_s7-1500_cpu_firmware
|
Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 and SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allows remote attack…
|
CWE-352
Origin Validation Error
|
CVE-2014-2249
|
2014-03-26 13:57 |
2014-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258778
|
- |
|
libpng
|
libpng
|
The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an…
|
CWE-189
Numeric Errors
|
CVE-2014-0333
|
2014-03-26 13:56 |
2014-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258779
|
- |
|
libssh
|
libssh
|
The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset the state of the OpenSSL pseudo-random number generator (PRNG), which causes the state to be shared be…
|
CWE-310
Cryptographic Issues
|
CVE-2014-0017
|
2014-03-26 13:55 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258780
|
- |
|
roundcube
|
webmail
|
steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read …
|
CWE-89
SQL Injection
|
CVE-2013-6172
|
2014-03-26 13:54 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|