258171
|
- |
|
yiiframework
|
yiiframework
|
per http://www.yiiframework.com/news/78/yii-1-1-15-is-released-security-fix/:
"Note that the issue only affects 1.1.14. All previous releases are not affected"
|
CWE-94
Code Injection
|
CVE-2014-4672
|
2014-07-24 14:01 |
2014-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258172
|
- |
|
symantec
|
data_insight
|
Cross-site scripting (XSS) vulnerability in the management console in Symantec Data Insight 3.x and 4.x before 4.5 allows remote attackers to inject arbitrary web script or HTML via an unspecified fo…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3432
|
2014-07-24 14:00 |
2014-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258173
|
- |
|
symantec
|
data_insight
|
Cross-site scripting (XSS) vulnerability in the management console in Symantec Data Insight 3.x and 4.x before 4.5 allows remote attackers to inject arbitrary web script or HTML via an unspecified fo…
|
CWE-79
Cross-site Scripting
|
CVE-2014-3433
|
2014-07-24 14:00 |
2014-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258174
|
- |
|
juniper
|
junos srx100 srx110 srx1400 srx210 srx220 srx240 srx3400 srx3600 srx550 srx5600 srx5800 srx650
|
Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to cause a denial of service (flowd crash) via a crafted SIP packet.
|
CWE-20
Improper Input Validation
|
CVE-2014-3815
|
2014-07-24 14:00 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258175
|
- |
|
oracle
|
fusion_middleware
|
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system.
|
NVD-CWE-noinfo
|
CVE-2014-2424
|
2014-07-24 13:59 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258176
|
- |
|
hp
|
release_control
|
Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sens…
|
NVD-CWE-noinfo
|
CVE-2014-2612
|
2014-07-24 13:59 |
2014-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258177
|
- |
|
hp
|
release_control
|
Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to gain privil…
|
NVD-CWE-noinfo
|
CVE-2014-2613
|
2014-07-24 13:59 |
2014-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258178
|
- |
|
symantec
|
workspace_streaming
|
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-1649
|
2014-07-24 13:58 |
2014-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258179
|
- |
|
happyworm
|
jplayer
|
Cross-site scripting (XSS) vulnerability in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2023
|
2014-07-24 13:49 |
2013-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258180
|
- |
|
cybozu
|
garoon
|
Cross-site scripting (XSS) vulnerability in the Notices portlet in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified ve…
|
CWE-79
Cross-site Scripting
|
CVE-2014-1994
|
2014-07-24 03:55 |
2014-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|