257261
|
- |
|
siemens
|
simatic_pcs7 wincc
|
Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4685
|
2014-07-25 23:49 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257262
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4684
|
2014-07-25 23:42 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257263
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4683
|
2014-07-25 23:37 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257264
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.
|
CWE-200
Information Exposure
|
CVE-2014-4682
|
2014-07-25 23:27 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257265
|
- |
|
micropact
|
icomplaints
|
Cross-site scripting (XSS) vulnerability in AddStdLetter.jsp in MicroPact iComplaints before 8.0.2.1.8.8014 allows remote authenticated users to inject arbitrary web script or HTML via the descriptio…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2971
|
2014-07-25 23:00 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257266
|
- |
|
honeywell
|
falcon_xlweb_linux_controller falcon_xlweb_xlwebexe
|
Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain adminis…
|
NVD-CWE-Other
|
CVE-2014-2717
|
2014-07-25 22:52 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257267
|
- |
|
honeywell
|
falcon_xlweb_linux_controller falcon_xlweb_xlwebexe
|
<a href="http://cwe.mitre.org/data/definitions/552.html" target="_blank">CWE-552: CWE-552: Files or Directories Accessible to External Parties</a>
|
NVD-CWE-Other
|
CVE-2014-2717
|
2014-07-25 22:52 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257268
|
- |
|
huawei
|
e355_web_ui e355_firmware e355
|
Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI 11.001.08.00.03 allows remote attackers to inject arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2014-2968
|
2014-07-25 03:49 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257269
|
- |
|
huawei
|
e355_web_ui e355_firmware e355
|
Per: http://www.kb.cert.org/vuls/id/688812
"The following device configuration was reported to be vulnerable. Other versions may be affected:
Hardware version: CH1E355SM
Software version: 21.157.37…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2968
|
2014-07-25 03:49 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257270
|
- |
|
omron
|
ns_series_system_program_firmware ns10_hmi_terminal ns12_hmi_terminal ns15_hmi_terminal ns5_hmi_terminal ns8_hmi_terminal
|
Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to hijack the authen…
|
CWE-352
Origin Validation Error
|
CVE-2014-2369
|
2014-07-25 03:29 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|