Show filters
461 Total Results
Displaying 271-280 of 461
Sort by:
Attacker Value
Unknown

CVE-2014-4624

Disclosure Date: October 25, 2014 (last updated October 05, 2023)
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and GSAN passwords via a crafted call.
0
Attacker Value
Unknown

CVE-2014-7527

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The Savage Nation Mobile Web (aka com.wSavageNation) application 0.57.13354.63350 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7462

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Fashion Story: Neon 90's (aka com.teamlava.fashionstory39) application 1.5.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-6932

Disclosure Date: October 04, 2014 (last updated October 05, 2023)
The All Navalny (aka com.all.navalny) application 1.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-2376

Disclosure Date: September 15, 2014 (last updated October 05, 2023)
SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-2375

Disclosure Date: September 15, 2014 (last updated October 05, 2023)
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.
0
Attacker Value
Unknown

CVE-2014-2377

Disclosure Date: September 15, 2014 (last updated October 05, 2023)
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.
0
Attacker Value
Unknown

CVE-2014-5857

Disclosure Date: September 10, 2014 (last updated October 05, 2023)
The White & Yellow Pages (aka com.avantar.wny) application 5.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-0786

Disclosure Date: May 01, 2014 (last updated October 05, 2023)
Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role.
0
Attacker Value
Unknown

CVE-2013-7175

Disclosure Date: January 24, 2014 (last updated October 05, 2023)
Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.
0