256801
|
- |
|
openstack canonical
|
keystone ubuntu_linux
|
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for to…
|
CWE-255
Credentials Management
|
CVE-2014-5251
|
2014-10-10 14:23 |
2014-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256802
|
- |
|
openstack canonical
|
keystone ubuntu_linux
|
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the tok…
|
CWE-255
Credentials Management
|
CVE-2014-5252
|
2014-10-10 14:23 |
2014-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256803
|
- |
|
openstack canonical
|
keystone ubuntu_linux
|
OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access …
|
CWE-255
Credentials Management
|
CVE-2014-5253
|
2014-10-10 14:23 |
2014-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256804
|
- |
|
drupal
|
drupal
|
modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5267
|
2014-10-10 14:23 |
2014-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256805
|
- |
|
alex_kellner
|
powermail
|
Unrestricted file upload vulnerability in the powermail extension before 1.6.11 and 2.x before 2.0.14 for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with a crafted ex…
|
CWE-94
Code Injection
|
CVE-2014-3947
|
2014-10-10 14:22 |
2014-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256806
|
- |
|
alex_kellner
|
powermail
|
Vendor advisory - http://typo3.org/teams/security/security-bulletins/typo3-extensions/typo3-ext-sa-2014-007/
|
CWE-94
Code Injection
|
CVE-2014-3947
|
2014-10-10 14:22 |
2014-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256807
|
- |
|
oracle
|
sun_glassfish_enterprise_server
|
Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.0.1 and 3.1.1 allows remote attackers to affect confidentiality and integrity, related to JSF.
|
NVD-CWE-noinfo
|
CVE-2011-4358
|
2014-10-10 13:43 |
2012-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256808
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-7982
|
2014-10-10 10:50 |
2014-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256809
|
- |
|
joomla
|
joomla\!
|
Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving GMail authentication.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7984
|
2014-10-10 10:49 |
2014-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
256810
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in com_contact in Joomla! CMS 3.1.2 through 3.2.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-7983
|
2014-10-10 10:43 |
2014-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|