Search Results (24187 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-5170 1 Drupal 1 Storage Api 2024-11-21 N/A
The Storage API module 7.x before 7.x-1.6 for Drupal might allow remote attackers to execute arbitrary code by leveraging failure to update .htaccess file contents after SA-CORE-2013-003.
CVE-2014-5132 1 Avolvesoftware 1 Projectdox 2024-11-21 N/A
Avolve Software ProjectDox 8.1 allows remote attackers to enumerate users via vectors related to email addresses.
CVE-2014-5131 1 Avolvesoftware 1 Projectdox 2024-11-21 N/A
Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse.
CVE-2014-5130 1 Avolvesoftware 1 Projectdox 2024-11-21 N/A
Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via vectors involving a direct access token.
CVE-2014-5118 3 Fedoraproject, Redhat, Trusted Boot Project 3 Fedora, Enterprise Linux, Trusted Boot 2024-11-21 5.5 Medium
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
CVE-2014-5092 1 Status2k 1 Status2k 2024-11-21 8.8 High
Status2k allows Remote Command Execution in admin/options/editpl.php.
CVE-2014-5091 1 Status2k 1 Status2k 2024-11-21 9.8 Critical
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.
CVE-2014-5087 3 Sphider, Sphider-plus, Sphiderpro 3 Sphider, Sphider-plus, Sphider Pro 2024-11-21 9.8 Critical
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.
CVE-2014-5028 1 Reviewboard 1 Review Board 2024-11-21 N/A
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass intended access restrictions and obtain sensitive information from repository files by leveraging knowledge of database ids.
CVE-2014-5011 1 Dompdf Project 1 Dompdf 2024-11-21 6.5 Medium
DOMPDF before 0.6.2 allows Information Disclosure.
CVE-2014-5004 1 Brbackup Project 1 Brbackup 2024-11-21 N/A
lib/brbackup.rb in the brbackup gem 0.1.1 for Ruby places the database password on the mysql command line, which allows local users to obtain sensitive information by listing the process.
CVE-2014-5003 1 Ciborg Project 1 Ciborg 2024-11-21 N/A
chef/travis-cookbooks/ci_environment/perlbrew/recipes/default.rb in the ciborg gem 3.0.0 for Ruby allows local users to write to arbitrary files and gain privileges via a symlink attack on /tmp/perlbrew-installer.
CVE-2014-5001 1 Kcapifony Project 1 Kcapifony 2024-11-21 N/A
lib/ksymfony1.rb in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) mysqldump, (2) pg_dump, (3) mysql, and (4) psql command lines, which allows local users to obtain sensitive information by listing the processes.
CVE-2014-5000 1 Lawn-login Project 1 Lawn-login 2024-11-21 N/A
The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.
CVE-2014-4999 1 Kajam Project 1 Kajam 2024-11-21 N/A
vendor/plugins/dataset/lib/dataset/database/mysql.rb in the kajam gem 1.0.3.rc2 for Ruby places the mysql user password on the (1) mysqldump command line in the capture function and (2) mysql command line in the restore function, which allows local users to obtain sensitive information by listing the process.
CVE-2014-4998 1 Lean-ruport Project 1 Lean-ruport 2024-11-21 N/A
test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
CVE-2014-4997 1 Point-cli Project 1 Point-cli 2024-11-21 N/A
lib/commands/setup.rb in the point-cli gem 0.0.1 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.
CVE-2014-4995 1 Vladtheenterprising Project 1 Vladtheenterprising 2024-11-21 N/A
Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensitive information by reading the MySQL root password from a temporary file before it is removed.
CVE-2014-4994 1 Gyazo Project 1 Gyazo 2024-11-21 N/A
lib/gyazo/client.rb in the gyazo gem 1.0.0 for Ruby allows local users to write to arbitrary files via a symlink attack on a temporary file, related to time-based filenames.
CVE-2014-4993 2 Backup-agoddard Project, Backup Checksum Project 2 Backup-agoddard, Backup Checksum 2024-11-21 N/A
(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obtain sensitive information by listing the process.