Search:
WLB2

[ Bugs ]   [ Exploits ]
WLB2RSS Bugtraq WLB2RSS
[ Bogus ]   [ Tricks ]
2014-10-20
Medium Risk

Newtelligence dasBlog Open Redirect Vulnerability

(CVE)
Wang Jing
2014-10-19
High Risk

MacOS X 10.9 Hard Link Memory Corruption PoC

(CVE)
CXSECURITY
Medium Risk

Linux PolicyKit Race Condition Privilege Escalation

(CVE)
xi4oyu
Medium Risk

Centreon SQL Injection / Command Injection

(CVE)
MaZ
2014-10-18
High Risk

MacOSX 10.9/XNU HFS Kernel Multiple Vulnerabilities

(CVE)
CXSECURITY
High Risk

MS14-060 Microsoft Windows OLE Package Manager Code Execution

(CVE)
Juan vazquez
High Risk

Fonality Trixbox CE 2.8.0.4 Command Execution

Simo Ben youssef
High Risk

Elastix 2.4.0 Stable XSS / CSRF / Command Execution

Simo Ben youssef
High Risk

Drupal HTTP Parameter Key/Value SQL Injection

(CVE)
Brandon
2014-10-17
Medium Risk

Bypassing HTTP Strict Transport Security

Jose Selvi
Low Risk

Abusing TZ for fun (and little profit)

Jakub Wilk
High Risk

SAP BusinessObjects Explorer 14.0.5 XXE Injection

(CVE)
Stefan Horlacher
Medium Risk

IPy Blacklist Bypass

Nicolas
Medium Risk

NETIS DL4322D XSS / CSRF / DoS

AkaStep
Low Risk

New York Times Cross Site Scripting

Wang Jing
Low Risk

OpenX 2.8.10 Open Redirect

(CVE)
Wang Jing
Medium Risk

SAP Netweaver Enqueue Server Trace Pattern Denial Of Service

(CVE)
CORE
2014-10-16
High Risk

Drupal 7.x SQL Injection Exploit

fyukyuk
High Risk

Drupal 7.31 CORE pre Auth SQL Injection Vulnerability *youtube

Stefan Horst
Medium Risk

Microsoft Bluetooth Personal Area Networking Privilege Escalation

(CVE)
Jay Smith
Medium Risk

SEO Control Panel 3.6.0 SQL Injection

Tiago Carvalho
Low Risk

Tenda A32 Cross Site Request Forgery

(CVE)
zixian
Low Risk

WordPress WP Google Maps 6.0.26 Cross Site Scripting

(CVE)
High-Tech Bridge...
Low Risk

WordPress MaxButtons 1.26.0 Cross Site Scripting

(CVE)
High-Tech Bridge...
Low Risk

ADF Faces 12.1.2.0 Cross Site Scripting

W. Ettlinger
Medium Risk

PayPal Inc Shipping Cross Site Scripting

Vulnerability La...
Low Risk

PayPal Inc MultiOrderShipping API Filter Bypass / Persistent XML

Vulnerability La...
High Risk

PayPal Inc PDF Mailer Buffer Overflow

Vulnerability La...
2014-10-15
High Risk

SSL 3.0 fallback Design Vulnerability

Google Team
Low Risk

Indeed Job Search 2.5 iOS API Multiple Vulnerabilities

Vulnerability La...
Medium Risk

YourMembers Blind SQL Injection

Tien Tran Dinh
2014-10-14
High Risk

Bosch Security Systems DVR 630/650/670 Series Multiple Vulnerabilities

dun
High Risk

DNS Reverse Lookup Shellshock

(CVE)
Dirk-Willem van ...
Medium Risk

Pagekit 0.8.7 Cross Site Scripting / Open Redirect

(CVE)
Mahendra
Low Risk

Blackberry.com Open Redirect

Claudio Viviani
[ Read More ]

  Top CWE:   CWE-89 (SQL Injection)   CWE-79 (XSS)   CWE-119 (Buffer Overflow)   CWE-22 (Path Traversal)  

[ CVE Related ]   [ CWE Related ]   [ Dorks ]  

[ CVE Products ] [ CVE Vendors ]
WLB2RSS CVE CVEMAP.ORG WLB2RSS CVE
Last Update: 2014-10-20
2014-10-15
 
CVE-2014-0558
( 10/10 )
 
  Adobe Adobe air
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attacker...
 
CVE-2014-0564
( 10/10 )
 
  Adobe Adobe air
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attacker...
 
CVE-2014-0569
( 10/10 )
 
  Adobe Adobe air
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0....
 
CVE-2014-0570
( 6.8/10 )
 
  Adobe Coldfusion
Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to hijack the authentication of unspecified v...
 
CVE-2014-0571
( 4.3/10 )
 
  Adobe Coldfusion
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecifi...
 
CVE-2014-0572
( 4.6/10 )
 
  Adobe Coldfusion
Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows local users to bypass intended IP-based access restrictions via unspecified vectors.
 
CVE-2014-4073
( 10/10 )
 
  Microsoft .net framework
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET Clic...
 
CVE-2014-4075
( 4.3/10 )
 
  Microsoft Asp.net model view controller
Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 through 5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted web page, aka "MVC XSS Vulnerability."
 
CVE-2014-4113
( 7.2/10 )
 
  Microsoft Windows 7
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users ...
 
CVE-2014-4114
( 9.3/10 )
 
  Microsoft Windows 7
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Offic...
 
CVE-2014-4115
( 7.2/10 )
 
  Microsoft Windows server 2003
fastfat.sys (aka the FASTFAT driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly allocate memory, which allows physically proximate attackers to execute arbitrary code or cause a d...
 
CVE-2014-4117
( 9.3/10 )
 
  Microsoft Office
Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 al...
 
CVE-2014-4121
( 10/10 )
 
  Microsoft .net framework
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf...
 
CVE-2014-4122
( 4.3/10 )
 
  Microsoft .net framework
Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addresses by leveraging the predictability of an executable image's location,...
 
CVE-2014-4123
( 6.8/10 )
 
  Microsoft Internet explorer
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-201...
 
CVE-2014-4124
( 6.8/10 )
 
  Microsoft Internet explorer
Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-4123.
 
CVE-2014-4126
( 9.3/10 )
 
  Microsoft Internet explorer
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
 
CVE-2014-4127
( 9.3/10 )
 
  Microsoft Internet explorer
Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
 
CVE-2014-4128
( 9.3/10 )
 
  Microsoft Internet explorer
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
 
CVE-2014-4129
( 9.3/10 )
 
  Microsoft Internet explorer
Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
[ Read More ]

Top Vendors:

Apple   Microsoft   Google   Oracle   Apache   IBM   Red Hat   HP   Adobe   Mozilla  

[ Full List of Vendors ]  

Top Products:

Linux Kernel   Mac OS X   Windows XP   Windows 7   Flash Player   Adobe Reader   PHP   JRE   JDK  
Wordpress   Joomla   Chrome   IE   Firefox   Safari   HTTPD   Tomcat   Nginx  

[ Full List of Products ]  



 
Copyright 2014, cxsecurity.com