CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2014-6480

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to System management.

    Published: 21 Jan 2015
    4.9
    Medium

    CVE-2014-6509

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 allows local users to affect availability via unknown vectors related to Kernel.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2014-6514

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PL/SQL component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 21 Jan 2015
    6.6
    Medium

    CVE-2014-6518

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11 allows local users to affect integrity and availability via vectors related to Unix File System (UFS).

    Published: 21 Jan 2015
    7.2
    High

    CVE-2014-6521

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 allows local users to affect confidentiality, integrity, and availability via vectors related to CDE - Power Management Utility.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2014-6528

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel Core - System Management component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Server Infrastructure.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2015-0391

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2015-1205

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 40.0.2214.91 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2015-8478

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.73, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7923

    Last Modified: 12 Apr 2025

    The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7926

    Last Modified: 12 Apr 2025

    The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7928

    Last Modified: 12 Apr 2025

    hydrogen.cc in Google V8, as used Google Chrome before 40.0.2214.91, does not properly handle arrays with holes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers an array copy.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7929

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the HTMLScriptElement::didMoveToNewDocument function in core/html/HTMLScriptElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving movement of a SCRIPT element across documents.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7935

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in browser/speech/tts_message_filter.cc in the Speech implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving utterances from a closed tab.

    Published: 21 Jan 2015
    6.8
    Medium

    CVE-2014-7936

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the ZoomBubbleView::Close function in browser/ui/views/location_bar/zoom_bubble_view.cc in the Views implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document that triggers improper maintenance of a zoom bubble.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7938

    Last Modified: 12 Apr 2025

    The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2014-7939

    Last Modified: 12 Apr 2025

    Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-7941

    Last Modified: 12 Apr 2025

    The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7942

    Last Modified: 12 Apr 2025

    The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-8157

    Last Modified: 12 Apr 2025

    Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

    Published: 21 Jan 2015
    6.8
    Medium

    CVE-2014-8158

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2014-6568

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2015-0374

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-0381

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2015-0382

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.

    Published: 21 Jan 2015
    3.5
    Low

    CVE-2015-0385

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Pluggable Auth.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2015-0432

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-7947

    Last Modified: 12 Apr 2025

    OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, pi.c, t1.c, t2.c, and tcd.c.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-7924

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the IndexedDB implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering duplicate BLOB references, related to content/browser/indexed_db/indexed_db_callbacks.cc and content/browser/indexed_db/indexed_db_dispatcher_host.cc.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7925

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the WebAudio implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an audio-rendering thread in which AudioNode data is improperly maintained.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7927

    Last Modified: 12 Apr 2025

    The SimplifiedLowering::DoLoadBuffer function in compiler/simplified-lowering.cc in Google V8, as used in Google Chrome before 40.0.2214.91, does not properly choose an integer data type, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7930

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in core/events/TreeScopeEventContext.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers improper maintenance of TreeScope data.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7931

    Last Modified: 12 Apr 2025

    factory.cc in Google V8, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers improper maintenance of backing-store pointers.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7932

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the Element::detach function in core/dom/Element.cpp in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving pending updates of detached elements.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7933

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the matroska_read_seek function in libavformat/matroskadec.c in FFmpeg before 2.5.1, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Matroska file that triggers improper maintenance of tracks data.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7934

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the DOM implementation in Blink, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to unexpected absence of document data structures.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7937

    Last Modified: 12 Apr 2025

    Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted Vorbis I data.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2014-7940

    Last Modified: 12 Apr 2025

    The collator implementation in i18n/ucol.cpp in International Components for Unicode (ICU) 52 through SVN revision 293126, as used in Google Chrome before 40.0.2214.91, does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted character sequence.

    Published: 21 Jan 2015
    4.3
    Medium

    CVE-2014-7948

    Last Modified: 12 Apr 2025

    The AppCacheUpdateJob::URLFetcher::OnResponseStarted function in content/browser/appcache/appcache_update_job.cc in Google Chrome before 40.0.2214.91 proceeds with AppCache caching for SSL sessions even if there is an X.509 certificate error, which allows man-in-the-middle attackers to spoof HTML5 application content via a crafted certificate.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-7943

    Last Modified: 12 Apr 2025

    Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-7944

    Last Modified: 12 Apr 2025

    The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.91, does not properly handle odd values of image width, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-7945

    Last Modified: 12 Apr 2025

    OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document, related to j2k.c, jp2.c, and t2.c.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-7946

    Last Modified: 12 Apr 2025

    The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips captions during table layout in certain situations, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors related to the Fonts implementation.

    Published: 21 Jan 2015
    9.8
    Critical

    CVE-2014-9654

    Last Modified: 20 Apr 2025

    The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring that they can be represented in a 24-bit field, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted string, a related issue to CVE-2014-7923.

    Published: 21 Jan 2015
    4
    Medium

    CVE-2015-0409

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2015-0411

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.

    Published: 21 Jan 2015
    7.5
    High

    CVE-2015-1346

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 3.30.33.15, as used in Google Chrome before 40.0.2214.91, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 21 Jan 2015
    5
    Medium

    CVE-2014-8790

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.

    Published: 20 Jan 2015
    7.5
    High

    CVE-2014-8386

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file.

    Published: 20 Jan 2015
    6.8
    Medium

    CVE-2014-8625

    Last Modified: 12 Apr 2025

    Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

    Published: 20 Jan 2015