258021
|
- |
|
bib2html_project
|
bib2html
|
Cross-site scripting (XSS) vulnerability in the bib2html plugin 0.9.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the styleShortName parameter in an adminStyleAdd…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3870
|
2014-05-28 23:02 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258022
|
- |
|
cisco
|
nx-os nexus_7000 nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot mds_9000 mds_9100
|
The Message Transfer Service (MTS) in Cisco NX-OS before 6.2(7) on MDS 9000 devices and 6.0 before 6.0(2) on Nexus 7000 devices allows remote attackers to cause a denial of service (NULL pointer dere…
|
NVD-CWE-Other
|
CVE-2014-2201
|
2014-05-28 01:31 |
2014-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258023
|
- |
|
cisco
|
nx-os nexus_7000 nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot mds_9000 mds_9100
|
Per: http://cwe.mitre.org/data/definitions/476.html
"CWE-476: NULL Pointer Dereference"
|
NVD-CWE-Other
|
CVE-2014-2201
|
2014-05-28 01:31 |
2014-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258024
|
- |
|
cisco
|
nx-os
|
Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via an SSH …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2200
|
2014-05-28 01:09 |
2014-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258025
|
- |
|
cisco
|
nx-os nexus_7000 nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot
|
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1191
|
2014-05-28 01:05 |
2014-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258026
|
- |
|
imember360
|
imember360
|
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Emai…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3849
|
2014-05-27 23:36 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258027
|
- |
|
imember360
|
imember360
|
The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3848
|
2014-05-27 23:34 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258028
|
- |
|
emerson
|
deltav
|
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrat…
|
CWE-255
Credentials Management
|
CVE-2014-2350
|
2014-05-23 23:14 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258029
|
- |
|
emerson
|
deltav
|
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 allows local users to modify or read configuration files by leveraging engineering-level privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2349
|
2014-05-23 23:13 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258030
|
- |
|
f5
|
big-iq
|
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/auth…
|
CWE-255
Credentials Management
|
CVE-2014-3220
|
2014-05-23 13:08 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|