Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 640

Количество 77 640

ubuntu логотип

CVE-2014-9274

почти 12 лет назад

UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999".

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-9273

почти 12 лет назад

lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2014-9272

больше 11 лет назад

The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9271

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to inline attachments, as demonstrated by a .swf.jpeg filename.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2014-9270

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the projax_array_serialize_for_autocomplete function in core/projax_api.php in MantisBT 1.1.0a3 through 1.2.17 allows remote attackers to inject arbitrary web script or HTML via the "profile/Platform" field.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9269

больше 11 лет назад

Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2014-9258

больше 11 лет назад

SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2014-9253

больше 11 лет назад

The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF file, then accessing it via the media parameter to lib/exe/fetch.php.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9236

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) photographer_id or (2) _crumb parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9235

почти 12 лет назад

Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2014-9221

больше 11 лет назад

strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-9219

почти 12 лет назад

Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2014-9218

почти 12 лет назад

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2014-9164

почти 12 лет назад

Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0587.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2014-9163

почти 12 лет назад

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.

CVSS3: 7.8
EPSS: Средний
ubuntu логотип

CVE-2014-9162

почти 12 лет назад

Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to obtain sensitive information via unspecified vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2014-9157

почти 12 лет назад

Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2014-9140

почти 12 лет назад

Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2014-9130

почти 12 лет назад

scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2014-9117

почти 12 лет назад

MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging knowledge of a CAPTCHA answer for a public_key parameter value, as demonstrated by E4652 for the public_key value 0.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-9274

UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999".

CVSS2: 7.5
6%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9273

lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write.

CVSS2: 4.6
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9272

The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9271

Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to inline attachments, as demonstrated by a .swf.jpeg filename.

CVSS3: 5.4
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9270

Cross-site scripting (XSS) vulnerability in the projax_array_serialize_for_autocomplete function in core/projax_api.php in MantisBT 1.1.0a3 through 1.2.17 allows remote attackers to inject arbitrary web script or HTML via the "profile/Platform" field.

CVSS2: 4.3
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9269

Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.

CVSS2: 2.6
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9258

SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.

CVSS2: 6.5
3%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9253

The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF file, then accessing it via the media parameter to lib/exe/fetch.php.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9236

Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) photographer_id or (2) _crumb parameter.

CVSS2: 4.3
3%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9235

Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

CVSS2: 6.5
2%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9221

strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.

CVSS2: 5
4%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2014-9219

Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

CVSS2: 4.3
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9218

libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.

CVSS2: 5
11%
Средний
почти 12 лет назад
ubuntu логотип
CVE-2014-9164

Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0587.

CVSS2: 10
4%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9163

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.

CVSS3: 7.8
20%
Средний
почти 12 лет назад
ubuntu логотип
CVE-2014-9162

Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to obtain sensitive information via unspecified vectors.

CVSS2: 10
5%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9157

Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.

CVSS2: 7.5
6%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9140

Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.

CVSS2: 5
6%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2014-9130

scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.

CVSS2: 5
13%
Средний
почти 12 лет назад
ubuntu логотип
CVE-2014-9117

MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging knowledge of a CAPTCHA answer for a public_key parameter value, as demonstrated by E4652 for the public_key value 0.

CVSS2: 5
2%
Низкий
почти 12 лет назад

Уязвимостей на страницу