CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2014-8917

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media Analytics 1.3 before IF11 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Jan 2015
    7.2
    High

    CVE-2014-8920

    Last Modified: 12 Apr 2025

    Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.

    Published: 28 Jan 2015
    7.5
    High

    CVE-2015-0581

    Last Modified: 12 Apr 2025

    The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880.

    Published: 28 Jan 2015
    4
    Medium

    CVE-2015-1376

    Last Modified: 12 Apr 2025

    pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

    Published: 28 Jan 2015
    7.5
    High

    CVE-2015-1375

    Last Modified: 12 Apr 2025

    pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.

    Published: 28 Jan 2015
    1.9
    Low

    CVE-2015-1420

    Last Modified: 12 Apr 2025

    Race condition in the handle_to_path function in fs/fhandle.c in the Linux kernel through 3.19.1 allows local users to bypass intended size restrictions and trigger read operations on additional memory locations by changing the handle_bytes value of a file handle during the execution of this function.

    Published: 28 Jan 2015
    7.2
    High

    CVE-2014-7822

    Last Modified: 12 Apr 2025

    The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted splice system call, as demonstrated by use of a file descriptor associated with an ext4 filesystem.

    Published: 28 Jan 2015
    5.9
    Medium

    CVE-2015-0210

    Last Modified: 20 Apr 2025

    wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle attack.

    Published: 28 Jan 2015
    4
    Medium

    CVE-2014-9749

    Last Modified: 12 Apr 2025

    Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."

    Published: 28 Jan 2015
    7.5
    High

    CVE-2015-1243

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an attempt to unregister a MutationObserver object that is not currently registered.

    Published: 28 Jan 2015
    7.5
    High

    CVE-2015-1250

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 28 Jan 2015
    7.8
    High

    CVE-2015-2158

    Last Modified: 20 Apr 2025

    Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file.

    Published: 28 Jan 2015
    7.4
    High

    CVE-2015-8870

    Last Modified: 12 Apr 2025

    Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or possibly obtain sensitive information from process memory, via crafted width and length values in RLE4 or RLE8 data in a BMP file.

    Published: 28 Jan 2015
    4.3
    Medium

    CVE-2015-1366

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the image_user parameter.

    Published: 27 Jan 2015
    7.5
    High

    CVE-2015-1369

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Sequelize before 2.0.0-rc7 for Node.js allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Published: 27 Jan 2015
    4.3
    Medium

    CVE-2015-1370

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.

    Published: 27 Jan 2015
    7.5
    High

    CVE-2015-1367

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in index.php in CatBot 0.4.2 allows remote attackers to execute arbitrary SQL commands via the lastcatbot parameter.

    Published: 27 Jan 2015
    4.3
    Medium

    CVE-2015-1368

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4) users/3/permissions/ in api/v1/ or the (5) next_run parameter to api/v1/schedules/.

    Published: 27 Jan 2015
    5
    Medium

    CVE-2015-1365

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a .. (dot dot) in the q parameter.

    Published: 27 Jan 2015
    7.5
    High

    CVE-2015-1362

    Last Modified: 12 Apr 2025

    Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the maker element in an XML file.

    Published: 27 Jan 2015
    4.3
    Medium

    CVE-2015-1363

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Free Reprintables ArticleFR 3.0.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter to search/v/.

    Published: 27 Jan 2015
    7.5
    High

    CVE-2015-1364

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the getProfile function in system/profile.functions.php in Free Reprintables ArticleFR 3.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter to register/.

    Published: 27 Jan 2015
    7.5
    High

    CVE-2015-1371

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in custom/uploads/.

    Published: 27 Jan 2015
    7.5
    High

    CVE-2015-1372

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p parameter in an update action to admin.php.

    Published: 27 Jan 2015
    4.3
    Medium

    CVE-2015-1373

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter in a search request, (2) username in a login request, which is not properly handled when logging the event, or (3) page title in an insert action.

    Published: 27 Jan 2015
    6.8
    Medium

    CVE-2015-1374

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication of administrators for requests that conduct (1) cross-site scripting (XSS), (2) SQL injection, or (3) unrestricted file upload attacks.

    Published: 27 Jan 2015
    6.8
    Medium

    CVE-2014-5211

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.

    Published: 27 Jan 2015
    7.5
    High

    CVE-2015-1182

    Last Modified: 12 Apr 2025

    The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointer in the asn1_sequence linked list, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ASN.1 sequence in a certificate.

    Published: 27 Jan 2015
    10
    Critical

    CVE-2014-9197

    Last Modified: 5 Sept 2025

    The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.

    Published: 27 Jan 2015
    10
    Critical

    CVE-2014-9198

    Last Modified: 5 Sept 2025

    The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.

    Published: 27 Jan 2015
    4.6
    Medium

    CVE-2014-9646

    Last Modified: 12 Apr 2025

    Unquoted Windows search path vulnerability in the GoogleChromeDistribution::DoPostUninstallOperations function in installer/util/google_chrome_distribution.cc in the uninstall-survey feature in Google Chrome before 40.0.2214.91 allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% directory, as demonstrated by program.exe, a different vulnerability than CVE-2015-1205.

    Published: 27 Jan 2015
    6.8
    Medium

    CVE-2014-9647

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in PDFium, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, related to fpdfsdk/src/fpdfview.cpp and fpdfsdk/src/fsdk_mgr.cpp, a different vulnerability than CVE-2015-1205.

    Published: 27 Jan 2015
    4.3
    Medium

    CVE-2014-9648

    Last Modified: 12 Apr 2025

    components/navigation_interception/intercept_navigation_resource_throttle.cc in Google Chrome before 40.0.2214.91 on Android does not properly restrict use of intent: URLs to open an application after navigation to a web site, which allows remote attackers to cause a denial of service (loss of browser access to that site) via crafted JavaScript code, as demonstrated by pandora.com and the Pandora application, a different vulnerability than CVE-2015-1205.

    Published: 27 Jan 2015
    6.8
    Medium

    CVE-2015-1359

    Last Modified: 12 Apr 2025

    Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted PDF document, related to an "intra-object-overflow" issue, a different vulnerability than CVE-2015-1205.

    Published: 27 Jan 2015
    7.5
    High

    CVE-2015-1360

    Last Modified: 12 Apr 2025

    Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data that is improperly handled during text drawing, related to gpu/GrBitmapTextContext.cpp and gpu/GrDistanceFieldTextContext.cpp, a different vulnerability than CVE-2015-1205.

    Published: 27 Jan 2015
    6.8
    Medium

    CVE-2015-1361

    Last Modified: 12 Apr 2025

    platform/image-decoders/ImageFrame.h in Blink, as used in Google Chrome before 40.0.2214.91, does not initialize a variable that is used in calls to the Skia SkBitmap::setAlphaType function, which might allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted HTML document, a different vulnerability than CVE-2015-1205.

    Published: 27 Jan 2015
    7.5
    High

    CVE-2015-0224

    Last Modified: 20 Apr 2025

    qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted protocol sequence set. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0203.

    Published: 27 Jan 2015
    5.1
    Medium

    CVE-2013-7424

    Last Modified: 12 Apr 2025

    The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.

    Published: 27 Jan 2015
    10
    Critical

    CVE-2015-0235

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

    Published: 27 Jan 2015
    4.4
    Medium

    CVE-2015-0239

    Last Modified: 12 Apr 2025

    The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYSENTER instruction.

    Published: 27 Jan 2015
    5
    Medium

    CVE-2015-0223

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related to 0-10 connection handling.

    Published: 27 Jan 2015
    4.3
    Medium

    CVE-2014-9571

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/install.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the (1) admin_username or (2) admin_password parameter.

    Published: 26 Jan 2015
    4.3
    Medium

    CVE-2015-1178

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in cart.php in X-Cart 5.1.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) product_id or (2) category_id parameter.

    Published: 26 Jan 2015
    7.2
    High

    CVE-2014-8148

    Last Modified: 12 Apr 2025

    The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system bus and possibly execute arbitrary code with root privileges.

    Published: 26 Jan 2015
    7.5
    High

    CVE-2014-9572

    Last Modified: 12 Apr 2025

    MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.

    Published: 26 Jan 2015
    6
    Medium

    CVE-2014-9573

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in manage_user_page.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote administrators with FILE privileges to execute arbitrary SQL commands via the MANTIS_MANAGE_USERS_COOKIE cookie.

    Published: 26 Jan 2015
    4.3
    Medium

    CVE-2015-1179

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in data_point_details.shtm in Mango Automation 2.4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dpid, (2) dpxid, or (3) pid parameter.

    Published: 26 Jan 2015
    4.3
    Medium

    CVE-2015-1307

    Last Modified: 12 Apr 2025

    plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package.

    Published: 26 Jan 2015
    9.3
    Critical

    CVE-2015-0312

    Last Modified: 12 Apr 2025

    Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.

    Published: 26 Jan 2015
    5
    Medium

    CVE-2015-1381

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.

    Published: 26 Jan 2015