Total
210374 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2014-5665 | 1 Mr384 | 1 Mzone Login | 2014-12-03 | 5.4 MEDIUM | N/A |
| The Mzone Login (aka com.mr384.MzoneLogin) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
| CVE-2014-5992 | 1 Successsecrets Project | 1 Successsecrets | 2014-12-03 | 5.4 MEDIUM | N/A |
| The successsecrets (aka com.alek.successsecrets) application 1.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
| CVE-2014-5972 | 1 Loving.fm | 1 Loving - Couple Essential | 2014-12-03 | 5.4 MEDIUM | N/A |
| The Loving - Couple Essential (aka com.xiaoenai.app) application 4.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |||||
| CVE-2014-9179 | 1 Supportezzy Ticket System Project | 1 Supportezzy Ticket System | 2014-12-03 | 4.0 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the "URL (optional)" field in a new ticket. | |||||
| CVE-2014-9184 | 1 Zte | 1 Zxdsl | 2014-12-03 | 5.0 MEDIUM | N/A |
| ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi. | |||||
| CVE-2014-9183 | 1 Zte | 1 Zxdsl | 2014-12-03 | 10.0 HIGH | N/A |
| ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges. | |||||
| CVE-2014-9182 | 1 Anchorcms | 1 Anchor Cms | 2014-12-03 | 4.3 MEDIUM | N/A |
| models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header. | |||||
| CVE-2014-3988 | 1 Sunhater | 1 Kcfinder | 2014-12-03 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) file or (2) directory (folder) name of an uploaded file. | |||||
| CVE-2014-5284 | 1 Ossec | 1 Ossec | 2014-12-02 | 7.2 HIGH | N/A |
| host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts.deny and gain root privileges by creating the temporary files before automatic IP blocking is performed. | |||||
| CVE-2013-6494 | 2 Fedoraproject, Fedup Project | 2 Fedora, Fedup | 2014-12-02 | 2.1 LOW | N/A |
| fedup 0.9.0 in Fedora 19, 20, and 21 uses a temporary directory with a static name for its download cache, which allows local users to cause a denial of service (prevention of system updates). | |||||
| CVE-2014-9156 | 1 Filefield Project | 1 Filefield | 2014-12-01 | 4.0 MEDIUM | N/A |
| The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file. | |||||
| CVE-2014-9151 | 1 Services Project | 1 Services | 2014-12-01 | 7.5 HIGH | N/A |
| The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password. | |||||
| CVE-2014-9153 | 1 Services Project | 1 Services | 2014-12-01 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the callback parameter in a JSONP response. | |||||
| CVE-2014-9152 | 1 Services Project | 1 Services | 2014-12-01 | 7.5 HIGH | N/A |
| The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack. | |||||
| CVE-2014-5268 | 1 Fasttoggle Project | 1 Fasttoggle | 2014-12-01 | 5.8 MEDIUM | N/A |
| The Fasttoggle module 7.x-1.3 and 7.x-1.4 for Drupal allows remote attackers to block or unblock an account via a crafted user status link. | |||||
| CVE-2014-8749 | 1 Ait-pro | 1 Bulletproof Security | 2014-12-01 | 5.0 MEDIUM | N/A |
| Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter. | |||||
| CVE-2014-2233 | 1 Infoware | 1 Mapsuite | 2014-12-01 | 5.0 MEDIUM | N/A |
| Server-side request forgery (SSRF) vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to trigger requests to intranet servers via unspecified vectors. | |||||
| CVE-2014-8425 | 1 Arris | 1 Vap2500 Firmware | 2014-11-28 | 7.8 HIGH | N/A |
| The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files. | |||||
| CVE-2014-8424 | 1 Arris | 1 Vap2500 Firmware | 2014-11-28 | 7.8 HIGH | N/A |
| ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication. | |||||
| CVE-2014-8423 | 1 Arris | 1 Vap2500 Firmware | 2014-11-28 | 10.0 HIGH | N/A |
| Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors. | |||||
