258401
|
- |
|
rik_de_boer
|
revisioning
|
The Revisioning module 7.x-1.x before 7.x-1.6 for Drupal does not properly check node access permissions for content marked unpublished by the Scheduled module, which allows remote authenticated user…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4597
|
2014-06-25 00:10 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258402
|
- |
|
livezilla
|
livezilla
|
LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access by reading the file.
|
CWE-255
Credentials Management
|
CVE-2013-6223
|
2014-06-25 00:03 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258403
|
- |
|
autocomplete_widgets_project
|
autocomplete_widgets
|
The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-rc1 does not properly handle node permissi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1973
|
2014-06-25 00:01 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258404
|
- |
|
vinay_sajip
|
python-gnupg
|
python-gnupg before 0.3.5 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
|
NVD-CWE-Other
|
CVE-2013-7323
|
2014-06-24 23:59 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258405
|
- |
|
vinay_sajip
|
python-gnupg
|
Per: http://cwe.mitre.org/data/definitions/77.html
"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')"
|
NVD-CWE-Other
|
CVE-2013-7323
|
2014-06-24 23:59 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258406
|
- |
|
fail2ban
|
fail2ban
|
The (1) dshield.conf, (2) mail-buffered.conf, (3) mynetwatchman.conf, and (4) mynetwatchman.conf actions in action.d/ in Fail2ban before 0.8.5 allows local users to write to arbitrary files via a sym…
|
CWE-59
Link Following
|
CVE-2009-5023
|
2014-06-24 23:51 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258407
|
- |
|
gomlab
|
gom_media_player
|
GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file.
|
CWE-20
Improper Input Validation
|
CVE-2014-3216
|
2014-06-24 23:42 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258408
|
- |
|
freebsd
|
freebsd
|
The ktrace utility in the FreeBSD kernel 8.4 before p11, 9.1 before p14, 9.2 before p7, and 9.3-BETA1 before p1 uses an incorrect page fault kernel trace entry size, which allows local users to obtai…
|
CWE-20
Improper Input Validation
|
CVE-2014-3873
|
2014-06-24 23:41 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258409
|
- |
|
webmin
|
usermin
|
Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.
|
CWE-78
OS Command
|
CVE-2014-3883
|
2014-06-24 02:19 |
2014-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258410
|
- |
|
theforeman
|
foreman
|
Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fe…
|
CWE-22
Path Traversal
|
CVE-2014-4507
|
2014-06-24 00:05 |
2014-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|