CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2014-8612

    Last Modified: 12 Apr 2025

    Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allow local users to (1) gain privileges via the stream id to the setsockopt function, when setting the SCTIP_SS_VALUE option, or (2) read arbitrary kernel memory via the stream id to the getsockopt function, when getting the SCTP_SS_PRIORITY option.

    Published: 2 Feb 2015
    7.8
    High

    CVE-2014-8613

    Last Modified: 12 Apr 2025

    The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted RE_CONFIG chunk.

    Published: 2 Feb 2015
    3.5
    Low

    CVE-2015-1451

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457 allow remote authenticated users to inject arbitrary web script or HTML via the (1) WTP Name or (2) WTP Active Software Version field in a CAPWAP Join request.

    Published: 2 Feb 2015
    7.8
    High

    CVE-2015-1452

    Last Modified: 12 Apr 2025

    The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a denial of service (locked CAPWAP Access Controller) via a large number of ClientHello DTLS messages.

    Published: 2 Feb 2015
    5
    Medium

    CVE-2015-1453

    Last Modified: 12 Apr 2025

    The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers to obtain passwords and possibly other sensitive data by leveraging the key to decrypt data in the Shared Preferences.

    Published: 2 Feb 2015
    7.1
    High

    CVE-2015-1454

    Last Modified: 12 Apr 2025

    Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates, which allows man-in-the-middle attackers to spoof ProxySG Client Managers, and consequently modify configurations and execute arbitrary software updates, via a crafted certificate.

    Published: 2 Feb 2015
    6.8
    Medium

    CVE-2015-1049

    Last Modified: 12 Apr 2025

    The web server on Siemens SCALANCE X-200IRT switches with firmware before 5.2.0 allows remote attackers to hijack sessions via unspecified vectors.

    Published: 2 Feb 2015
    4.3
    Medium

    CVE-2015-1385

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Blubrry PowerPress Podcasting plugin before 6.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cat parameter in a powerpress-editcategoryfeed action in the powerpressadmin_categoryfeeds.php page to wp-admin/admin.php.

    Published: 2 Feb 2015
    4.3
    Medium

    CVE-2015-0866

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.9 before hotfix 7941 allow remote attackers to inject arbitrary web script or HTML via the (1) fromCustomer, (2) username, or (3) password parameter to HomePage.do.

    Published: 2 Feb 2015
    5
    Medium

    CVE-2015-1357

    Last Modified: 12 Apr 2025

    Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allow context-dependent attackers to discover password hashes by reading (1) files or (2) security logs.

    Published: 2 Feb 2015
    10
    Critical

    CVE-2015-1448

    Last Modified: 12 Apr 2025

    The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to bypass authentication and perform administrative actions via unspecified vectors.

    Published: 2 Feb 2015
    10
    Critical

    CVE-2015-1449

    Last Modified: 12 Apr 2025

    Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 2 Feb 2015
    4.3
    Medium

    CVE-2015-1383

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search key.

    Published: 2 Feb 2015
    6.5
    Medium

    CVE-2015-1393

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Photo Gallery plugin before 1.2.11 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the asc_or_desc parameter in a create gallery request in the galleries_bwg page to wp-admin/admin.php.

    Published: 2 Feb 2015
    7.5
    High

    CVE-2015-1450

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Restaurant Biller allows remote attackers to execute arbitrary SQL commands via the cid parameter in a category action to index.php.

    Published: 2 Feb 2015
    5
    Medium

    CVE-2014-6170

    Last Modified: 12 Apr 2025

    The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote attackers to obtain sensitive information by triggering a SOAP fault.

    Published: 2 Feb 2015
    5.8
    Medium

    CVE-2014-8918

    Last Modified: 12 Apr 2025

    IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 2 Feb 2015
    8.5
    High

    CVE-2014-6141

    Last Modified: 12 Apr 2025

    IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands.

    Published: 2 Feb 2015
    5.8
    Medium

    CVE-2015-0512

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in EMC Unisphere Central before 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter.

    Published: 2 Feb 2015
    5
    Medium

    CVE-2014-6136

    Last Modified: 12 Apr 2025

    IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 2 Feb 2015
    5.5
    Medium

    CVE-2014-7882

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP SiteScope 11.1x and 11.2x allows remote authenticated users to gain privileges via unknown vectors.

    Published: 2 Feb 2015
    6.8
    Medium

    CVE-2015-0596

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj67163.

    Published: 2 Feb 2015
    5
    Medium

    CVE-2015-0597

    Last Modified: 12 Apr 2025

    The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159.

    Published: 2 Feb 2015
    5
    Medium

    CVE-2015-0595

    Last Modified: 12 Apr 2025

    The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages from crafted GET requests, aka Bug ID CSCuj67079.

    Published: 2 Feb 2015
    9.8
    Critical

    CVE-2015-0313

    Last Modified: 21 Apr 2026

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

    Published: 2 Feb 2015
    6.5
    Medium

    CVE-2014-8630

    Last Modified: 12 Apr 2025

    Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.

    Published: 1 Feb 2015
    7.8
    High

    CVE-2014-7266

    Last Modified: 12 Apr 2025

    Algorithmic complexity vulnerability in Cybozu Remote Service Manager through 2.3.0 and 3.x through 3.1.2 allows remote attackers to cause a denial of service (CPU consumption) via vectors that trigger colliding hash-table keys. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1983.

    Published: 1 Feb 2015
    6.5
    Medium

    CVE-2014-7269

    Last Modified: 12 Apr 2025

    ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.3715 and earlier, and RT-N56U routers with firmware 3.0.0.4.376.3715 and earlier allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.

    Published: 1 Feb 2015
    7.5
    High

    CVE-2014-9200

    Last Modified: 5 Sept 2025

    Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB TCP/SL), Advantys DTM for OTB, Advantys DTM for STB, KINOS DTM, SOLO DTM, and Xantrex DTMs allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 1 Feb 2015
    6.8
    Medium

    CVE-2014-7270

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on ASUS JAPAN RT-AC87U routers with firmware 3.0.0.4.378.3754 and earlier, RT-AC68U routers with firmware 3.0.0.4.376.3715 and earlier, RT-AC56S routers with firmware 3.0.0.4.376.3715 and earlier, RT-N66U routers with firmware 3.0.0.4.376.3715 and earlier, and RT-N56U routers with firmware 3.0.0.4.376.3715 and earlier allows remote attackers to hijack the authentication of arbitrary users.

    Published: 1 Feb 2015
    7.8
    High

    CVE-2015-0869

    Last Modified: 12 Apr 2025

    I-O DATA DEVICE NP-BBRM routers allow remote attackers to cause a denial of service (SSDP reflection) via UPnP requests.

    Published: 1 Feb 2015
    7.5
    High

    CVE-2015-0868

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in Mrs. Shiromuku Perl CGI shiromuku(bu2)BBS before 2.91 allows remote attackers to execute arbitrary code by uploading an executable file.

    Published: 1 Feb 2015
    4.3
    Medium

    CVE-2015-0870

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in hb.cgi in Nishishi Factory Fumy News Clipper 2.x before 2.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Feb 2015
    6.4
    Medium

    CVE-2014-8268

    Last Modified: 12 Apr 2025

    QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request.

    Published: 1 Feb 2015
    4.3
    Medium

    CVE-2014-4632

    Last Modified: 12 Apr 2025

    VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 and the proxy client in EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x do not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certificate.

    Published: 1 Feb 2015
    5
    Medium

    CVE-2014-7287

    Last Modified: 12 Apr 2025

    The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

    Published: 1 Feb 2015
    9
    Critical

    CVE-2014-7288

    Last Modified: 12 Apr 2025

    Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.

    Published: 1 Feb 2015
    4.3
    Medium

    CVE-2014-8266

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body field.

    Published: 1 Feb 2015
    4.3
    Medium

    CVE-2014-8267

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the RID parameter.

    Published: 1 Feb 2015
    6.8
    Medium

    CVE-2015-0926

    Last Modified: 12 Apr 2025

    Labtech before 100.237 on Linux uses world-writable permissions for root-executed scripts, which allows local users to gain privileges by modifying a script file.

    Published: 1 Feb 2015
    6.8
    Medium

    CVE-2014-4483

    Last Modified: 12 Apr 2025

    Buffer overflow in FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font file in a PDF document.

    Published: 30 Jan 2015
    7.2
    High

    CVE-2014-8825

    Last Modified: 12 Apr 2025

    The kernel in Apple OS X before 10.10.2 does not properly perform identitysvc validation of certain directory-service functionality, which allows local users to gain privileges or spoof directory-service responses via unspecified vectors.

    Published: 30 Jan 2015
    2.1
    Low

    CVE-2014-8827

    Last Modified: 12 Apr 2025

    LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately upon being woken from sleep, which allows physically proximate attackers to obtain sensitive information by reading the screen.

    Published: 30 Jan 2015
    7.5
    High

    CVE-2014-8828

    Last Modified: 12 Apr 2025

    Sandbox in Apple OS X before 10.10 allows attackers to write to the sandbox-profile cache via a sandboxed app that includes a com.apple.sandbox segment in a path.

    Published: 30 Jan 2015
    7.5
    High

    CVE-2014-8829

    Last Modified: 12 Apr 2025

    SceneKit in Apple OS X before 10.10.2 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted app.

    Published: 30 Jan 2015
    6.8
    Medium

    CVE-2014-8830

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted accessor element in a Collada file.

    Published: 30 Jan 2015
    5
    Medium

    CVE-2014-8831

    Last Modified: 12 Apr 2025

    security_taskgate in Apple OS X before 10.10.2 allows attackers to read group-ACL-restricted keychain items of arbitrary apps via a crafted app with a signature from a (1) self-signed certificate or (2) Developer ID certificate.

    Published: 30 Jan 2015
    4.9
    Medium

    CVE-2014-8832

    Last Modified: 12 Apr 2025

    The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, which allows local users to obtain sensitive information by reading from this drive.

    Published: 30 Jan 2015
    2.1
    Low

    CVE-2014-4499

    Last Modified: 12 Apr 2025

    The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credentials in App Store logs, which allows local users to obtain sensitive information by reading a file.

    Published: 30 Jan 2015
    10
    Critical

    CVE-2014-8824

    Last Modified: 12 Apr 2025

    The kernel in Apple OS X before 10.10.2 does not properly validate IODataQueue object metadata fields, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 30 Jan 2015