Show filters
819 Total Results
Displaying 611-620 of 819
Sort by:
Attacker Value
Unknown

CVE-2015-1594

Disclosure Date: March 07, 2015 (last updated October 05, 2023)
Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a Trojan horse application file.
0
Attacker Value
Unknown

CVE-2015-2087

Disclosure Date: February 26, 2015 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-7943

Disclosure Date: January 22, 2015 (last updated October 05, 2023)
Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-7926

Disclosure Date: January 22, 2015 (last updated October 05, 2023)
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.
0
Attacker Value
Unknown

CVE-2014-7939

Disclosure Date: January 22, 2015 (last updated October 05, 2023)
Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.
0
Attacker Value
Unknown

CVE-2014-7941

Disclosure Date: January 22, 2015 (last updated October 05, 2023)
The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data.
0
Attacker Value
Unknown

CVE-2014-7942

Disclosure Date: January 22, 2015 (last updated October 05, 2023)
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-7923

Disclosure Date: January 22, 2015 (last updated October 05, 2023)
The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.
0
Attacker Value
Unknown

CVE-2014-10009

Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) notes parameter to the client page; (4) insu_name or (5) price parameter to the add_insurance_cat page; or (6) status[] parameter to the add_status page.
0
Attacker Value
Unknown

CVE-2014-10008

Disclosure Date: January 13, 2015 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authentication of administrators for requests that add (1) an administrator via a crafted request to the admin page, (2) an agent via a crafted request to the agent page, (3) a sub-agent via a crafted request to the sub_agent page, (4) a partner via a crafted request to the partner page, or (5) a client via a crafted request to the client page.
0