257841
|
- |
|
cisco
|
webex_advanced_recording_format_player webex_recording_format_player
|
Cisco WebEx Recording Format (WRF) player and Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allow remote attackers to cause a denial of servi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-2132
|
2014-05-8 22:21 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257842
|
- |
|
cisco
|
cisco_nexus_1000v_intercloud
|
Cisco Nexus 1000V InterCloud 5.2(1)IC1(1.2) and earlier for VMware allows remote attackers to bypass ACL deny statements via crafted (1) IGMPv2 or (2) IGMPv3 packets, aka Bug ID CSCug61691.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0685
|
2014-05-8 01:05 |
2014-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257843
|
- |
|
cisco
|
nx-os nexus_7000 nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot
|
Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136.
|
CWE-20
Improper Input Validation
|
CVE-2014-0684
|
2014-05-8 00:48 |
2014-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257844
|
- |
|
ayatana_project canonical
|
unity ubuntu_linux
|
Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is active, which allows physically proximate attackers to bypass the lock screen and ex…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3203
|
2014-05-7 23:09 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257845
|
- |
|
ayatana_project canonical
|
unity ubuntu_linux
|
Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3204
|
2014-05-7 23:09 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257846
|
- |
|
ayatana_project
|
unity
|
Unity before 7.2.1 does not properly handle entry activation, which allows physically proximate attackers to bypass the lock screen by holding the ENTER key, which triggers the process to crash.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3202
|
2014-05-7 22:43 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257847
|
- |
|
skyphe
|
file-gallery
|
The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting field…
|
CWE-94
Code Injection
|
CVE-2014-2558
|
2014-05-7 22:23 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257848
|
- |
|
mongodb
|
mongodb
|
The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remote authenticated users to cause a denial of service (crash) or read system memory via a crafted BSON obj…
|
CWE-20
Improper Input Validation
|
CVE-2012-6619
|
2014-05-7 12:45 |
2014-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257849
|
- |
|
nagios
|
plugins
|
The IPXPING_COMMAND in contrib/check_ipxping.c in Nagios Plugins 1.4.16 allows local users to gain privileges via a symlink attack on /tmp/ipxping/ipxping.
|
CWE-59
Link Following
|
CVE-2013-4215
|
2014-05-7 04:10 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257850
|
- |
|
redhat
|
jboss_web_framework_kit
|
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.
|
CWE-79
Cross-site Scripting
|
CVE-2014-0149
|
2014-05-7 04:07 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|