CVE-2014-8000 to CVE-2014-8999
122 CVEs with public proof-of-concept exploits.
- CVE-2014-80081 PoCAbsolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows…
- CVE-2014-80821 PoClib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified…
- CVE-2014-80871 PoCCross-site scripting (XSS) vulnerability in the post highlights plugin before 2.6.1 for WordPress allows remote attackers to inject…
- CVE-2014-81101 PoCMultiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow…
- CVE-2014-81422 PoCsUse-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before…
- CVE-2014-81451 PoCMultiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a…
- CVE-2014-81463 PoCsThe resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International…
- CVE-2014-81473 PoCsThe resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International…
- CVE-2014-82701 PoCBMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of…
- CVE-2014-82722 PoCsThe IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly…
- CVE-2014-82752 PoCsOpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which…
- CVE-2014-82952 PoCsSQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid…
- CVE-2014-83051 PoCOpen redirect vulnerability in the redir function in includes/function.php in C97net Cart Engine before 4.0 allows remote attackers to…
- CVE-2014-83061 PoCSQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attackers to execute…
- CVE-2014-83071 PoCMultiple cross-site scripting (XSS) vulnerabilities in skins/default/outline.tpl in C97net Cart Engine before 4.0 allow remote attackers…
- CVE-2014-83222 PoCsStack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute…
- CVE-2014-83352 PoCs(1) wp-dbmanager.php and (2) database-manage.php in the WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress place…
- CVE-2014-83361 PoCThe "Sql Run Query" panel in WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote attackers to read…
- CVE-2014-83371 PoCUnrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote…
- CVE-2014-83381 PoCCross-site scripting (XSS) vulnerability in vwrooms/js/jsor-jcarousel/examples/special_textscroller.php in the VideoWhisper Webcam plugins…
- CVE-2014-83473 PoCsAn Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro…
- CVE-2014-83562 PoCsThe web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions…
- CVE-2014-83572 PoCsbackupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows…
- CVE-2014-83581 PoCHuawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before…
- CVE-2014-83591 PoCUntrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code…
- CVE-2014-83612 PoCsKEVThe miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as…
- CVE-2014-83751 PoCSQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute…
- CVE-2014-83801 PoCCross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP…
- CVE-2014-83831 PoCThe InFocus IN3128HD projector with firmware 0.26 allows remote attackers to bypass authentication via a direct request to main.html.
- CVE-2014-83841 PoCThe InFocus IN3128HD projector with firmware 0.26 does not restrict access to cgi-bin/webctrl.cgi.elf, which allows remote attackers to…
- CVE-2014-83862 PoCsMultiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted…
- CVE-2014-83871 PoCcgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via…
- CVE-2014-83893 PoCscgi-bin/mft/wireless_mft.cgi in AirLive BU-2015 with firmware 1.03.18 16.06.2014, AirLive BU-3026 with firmware 1.43 21.08.2014, AirLive…
- CVE-2014-83901 PoCMultiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed…
- CVE-2014-83911 PoCThe Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive…
- CVE-2014-83932 PoCsDLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.
- CVE-2014-84201 PoCThe ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and…
- CVE-2014-84232 PoCsUnspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands…
- CVE-2014-84242 PoCsARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.
- CVE-2014-84251 PoCThe management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.
- CVE-2014-84291 PoCCross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers…
- CVE-2014-84402 PoCsAdobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR…
- CVE-2014-84692 PoCsCross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject…
- CVE-2014-84911 PoCThe Grand Flagallery plugin before 4.25 for WordPress allows remote attackers to obtain the installation path via a request to (1)…
- CVE-2014-84921 PoCMultiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for…
- CVE-2014-84934 PoCsZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to…
- CVE-2014-84985 PoCsSQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service…
- CVE-2014-84994 PoCsMultiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP)…
- CVE-2014-85071 PoCMultiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java…
- CVE-2014-85163 PoCsUnrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a…
- CVE-2014-85174 PoCsThe fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1…
- CVE-2014-85553 PoCsDirectory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11.2 allows remote attackers to read…
- CVE-2014-85772 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2014-85863 PoCsSQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL…
- CVE-2014-85962 PoCsMultiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the…
- CVE-2014-85982 PoCsThe XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files…
- CVE-2014-86031 PoCcloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary…
- CVE-2014-86041 PoCThe XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration…
- CVE-2014-86051 PoCThe XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with…
- CVE-2014-86061 PoCDirectory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to read…
- CVE-2014-86071 PoCThe XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command line, which allows…
- CVE-2014-86094 PoCsThe addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0…
- CVE-2014-86101 PoCAndroidManifest.xml in Android before 5.0.0 does not require the SEND_SMS permission for the SmsReceiver receiver, which allows attackers…
- CVE-2014-86121 PoCMultiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3…
- CVE-2014-86211 PoCSQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL…
- CVE-2014-86362 PoCsThe XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that…
- CVE-2014-86521 PoCElipse E3 3.x and earlier allows remote attackers to cause a denial of service (application crash and plant outage) via a rapid series of…
- CVE-2014-86532 PoCsCross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware…
- CVE-2014-86542 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway…
- CVE-2014-86552 PoCsThe Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to…
- CVE-2014-86562 PoCsThe Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of…
- CVE-2014-86572 PoCsThe Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to…
- CVE-2014-86733 PoCsMultiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in Simple Online…
- CVE-2014-86743 PoCsMultiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the document.cookie in…
- CVE-2014-86751 PoCSoplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote…
- CVE-2014-86762 PoCsDirectory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine…
- CVE-2014-86773 PoCsThe installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an…
- CVE-2014-86812 PoCsSQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before…
- CVE-2014-86823 PoCsMultiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to…
- CVE-2014-86842 PoCsCodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies…
- CVE-2014-86863 PoCsCodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption…
- CVE-2014-86876 PoCsSeagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by…
- CVE-2014-86902 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, and 2.3.x before…
- CVE-2014-87221 PoCGetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2)…
- CVE-2014-87272 PoCsMultiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or…
- CVE-2014-87282 PoCsSQL injection vulnerability in the login page (login/login) in Subex ROC Fraud Management (aka Fraud Management System and FMS) 7.4 and…
- CVE-2014-87311 PoCPHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the…
- CVE-2014-87394 PoCsUnrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the…
- CVE-2014-87412 PoCsDirectory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote…
- CVE-2014-87531 PoCMultiple cross-site scripting (XSS) vulnerabilities in Cit-e-Net Cit-e-Access 6.
- CVE-2014-87571 PoCLG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.
- CVE-2014-87581 PoCCross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject…
- CVE-2014-87672 PoCsInteger underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a…
- CVE-2014-87685 PoCsMultiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to…
- CVE-2014-87692 PoCstcpdump 3.8 through 4.6.2 might allow remote attackers to obtain sensitive information from memory or cause a denial of service (packet…
- CVE-2014-87702 PoCsUnrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for…
- CVE-2014-87731 PoCMODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1)…
- CVE-2014-87741 PoCCross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject…
- CVE-2014-87751 PoCMODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier…
- CVE-2014-87801 PoCCross-site scripting (XSS) vulnerability in Jease 2.11 allows remote authenticated users to inject arbitrary web script or HTML via a…
- CVE-2014-87912 PoCsproject/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct…
- CVE-2014-87994 PoCsDirectory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress…
- CVE-2014-88002 PoCsCross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for…
- CVE-2014-88013 PoCsDirectory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote…
- CVE-2014-88021 PoCThe Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which…
- CVE-2014-88102 PoCsSQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remote authenticated…
- CVE-2014-88262 PoCsLaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper…
- CVE-2014-88352 PoCsThe xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes key has the xpc_data…
- CVE-2014-88681 PoCEntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator…
- CVE-2014-88712 PoCsDirectory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1…
- CVE-2014-88722 PoCsImproper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23,…
- CVE-2014-88771 PoCThe alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4…
- CVE-2014-88891 PoCDropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by…
- CVE-2014-89041 PoClquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV…
- CVE-2014-89482 PoCsCross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to…
- CVE-2014-89492 PoCsThe iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via…
- CVE-2014-89532 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to hijack the…
- CVE-2014-89542 PoCsMultiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2014-89571 PoCCross-site scripting (XSS) vulnerability in OpenKM before 6.4.19 allows remote authenticated users to inject arbitrary web script or HTML…
- CVE-2014-89951 PoCSQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the UserId cookie.
- CVE-2014-89972 PoCsUnrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 allows remote…
- CVE-2014-89983 PoCslib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header…