CVE-2014-7000 to CVE-2014-7999
58 CVEs with public proof-of-concept exploits.
- CVE-2014-71401 PoCUnspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.x…
- CVE-2014-71463 PoCsThe XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1)…
- CVE-2014-71531 PoCSQL injection vulnerability in the editgallery function in admin/gallery_func.php in the Huge-IT Image Gallery plugin 1.0.1 for WordPress…
- CVE-2014-716923 PoCsKEVGNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment…
- CVE-2014-71731 PoCFarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx25MonProxy.php,…
- CVE-2014-71741 PoCFarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature.
- CVE-2014-71751 PoCFarLinX X25 Gateway through 2014-09-25 allows attackers to write arbitrary data to fsUI.xyz via fsSaveUIPersistence.php.
- CVE-2014-71763 PoCsSQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the…
- CVE-2014-71771 PoCXML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a…
- CVE-2014-71781 PoCEnalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the…
- CVE-2014-71821 PoCMultiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to…
- CVE-2014-71832 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attackers to inject…
- CVE-2014-71868 PoCsThe redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service…
- CVE-2014-71875 PoCsOff-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial…
- CVE-2014-71901 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of…
- CVE-2014-71921 PoCEval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application…
- CVE-2014-72001 PoCCross-site scripting (XSS) vulnerability in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol) extension 2.14.0 and…
- CVE-2014-72011 PoCMultiple SQL injection vulnerabilities in the search function in pi1/class.tx_dmmjobcontrol_pi1.php in the JobControl (dmmjobcontrol)…
- CVE-2014-72056 PoCsEval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server…
- CVE-2014-72082 PoCsGParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted…
- CVE-2014-72213 PoCsTeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash)…
- CVE-2014-72223 PoCsBuffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash)…
- CVE-2014-72262 PoCsThe file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading…
- CVE-2014-72282 PoCsAkeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for…
- CVE-2014-72351 PoChtdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11…
- CVE-2014-72364 PoCsEval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the…
- CVE-2014-72381 PoCThe WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS
- CVE-2014-72401 PoCCross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to…
- CVE-2014-72792 PoCsThe Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management…
- CVE-2014-72802 PoCsCross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject…
- CVE-2014-72812 PoCsCross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote…
- CVE-2014-72853 PoCsThe management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS…
- CVE-2014-72861 PoCBuffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local users to gain…
- CVE-2014-72882 PoCsSymantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute…
- CVE-2014-72891 PoCSQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data…
- CVE-2014-73011 PoCSGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and…
- CVE-2014-73022 PoCsSGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of…
- CVE-2014-78091 PoCApache Struts 2.0.0 through 2.3.x before 2.3.20 uses predictable <s:token/> values, which allows remote attackers to bypass the CSRF…
- CVE-2014-78162 PoCsDirectory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when…
- CVE-2014-78221 PoCThe implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum…
- CVE-2014-78623 PoCsThe DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create…
- CVE-2014-78634 PoCsThe FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through…
- CVE-2014-78642 PoCsMultiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through…
- CVE-2014-78663 PoCsMultiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social…
- CVE-2014-78683 PoCsMultiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow…
- CVE-2014-78721 PoCComodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges by connecting to…
- CVE-2014-78831 PoCHP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive…
- CVE-2014-78841 PoCMultiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors.
- CVE-2014-79109 PoCsMultiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have…
- CVE-2014-79116 PoCsluni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify…
- CVE-2014-79202 PoCsmediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than…
- CVE-2014-79211 PoCmediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than…
- CVE-2014-79512 PoCsDirectory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a…
- CVE-2014-79523 PoCsThe backup mechanism in the adb tool in Android might allow attackers to inject additional applications (APKs) and execute arbitrary code…
- CVE-2014-79581 PoCCross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress…
- CVE-2014-79591 PoCSQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote…
- CVE-2014-79811 PoCSQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2014-79922 PoCsThe DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential…