Unknown · CVSS Not scored
Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of service via a crafted packet.
Published Feb 26, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view private IP addresses and other sensitive information.
Published Feb 4, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.
Published Feb 4, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.
Published Feb 5, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Brother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate attackers to gain unauthorized access.
Published Feb 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in the JetMPG.ax module in jetAudio 8.0.17 allows remote attackers to execute arbitrary code via a crafted MPEG2-TS video file, related to the MPEG2 transport stream.
Published Feb 5, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Brother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view sensitive information from referrer logs due to inadequate handling of HTTP referrer headers.
Published Feb 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.
Published Feb 6, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7) submit_button parameter to storage/apply.cgi.
Published Feb 18, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.
Published Feb 5, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.
Published Feb 5, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Brother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote attackers to obtain sensitive information.
Published Feb 5, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published Feb 6, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
Published Feb 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.
Published Feb 12, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.
Published Feb 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
TinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive information through the parameters "twg_browserx" and "twg_browsery" in the page image.php.
Published Feb 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the description in a project folder.
Published Feb 11, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site Scripting (XSS) in UebiMiau 2.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the "selected_theme" parameter in error.php.
Published Feb 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.
Published Feb 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php.
Published Feb 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a specially crafted URL request.
Published Feb 3, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server 6.6.x before 6.6.3 and 7.0.x before 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php/mail/viewmessage/getattachment/folder/INBOX/uniqueId/<MessageID>/filenameOriginal/.
Published Feb 12, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A vulnerability in Mambo CMS v4.6.5 where the scripts thumbs.php, editorFrame.php, editor.php, images.php, manager.php discloses the root path of the webserver.
Published Feb 15, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php/user/setLogin.
Published Feb 28, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell.
Published Feb 15, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ff_h264_decode_seq_parameter_set function in h264_ps.c in libavcodec in FFmpeg before 1.1.3 does not validate the relationship between luma depth and chroma depth, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted H.264 data.
Published Feb 27, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."
Published Feb 23, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.
Published Feb 11, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
Published Feb 8, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.
Published Feb 10, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
Published Feb 10, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.
Published Feb 11, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress plugin wp-cleanfix has Remote Code Execution
Published Feb 10, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ZPanel through 10.1.0 has Remote Command Execution
Published Feb 12, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal server error," which includes the username and password in an error message.
Published Feb 5, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
YaBB through 2.5.2: 'guestlanguage' Cookie Parameter Local File Include Vulnerability
Published Feb 11, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in flashmediaelement.swf in MediaElement.js before 2.11.2, as used in ownCloud Server 5.0.x before 5.0.5 and 4.5.x before 4.5.10, allows remote attackers to inject arbitrary web script or HTML via the file parameter.
Published Feb 5, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
Published Feb 12, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.
Published Feb 13, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and reading the information that is outside of wicket:panel markup.
Published Feb 10, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the get_dsmp function in loaders/masi_load.c in libxmp before 4.1.0 allows remote attackers to execute arbitrary code via a crafted MASI file.
Published Feb 11, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress Super Cache Plugin 1.3 has XSS.
Published Feb 7, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpreted sentence that lacks certain fields and a terminator. NOTE: a separate issue in the AIS driver was also reported, but it might not be a vulnerability.
Published Feb 6, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
Published Feb 19, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Commerce Skrill (Formerly Moneybookers) has an Access bypass vulnerability in all versions prior to 7.x-1.2
Published Feb 12, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.
Published Feb 8, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Zimbra 2013 has XSS in aspell.php
Published Feb 12, 2020 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.
Published Feb 5, 2014 · Updated Aug 6, 2024