CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2014-7865

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its requester. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Jan 2015
    9.8
    Critical

    CVE-2016-5008

    Last Modified: 12 Apr 2025

    libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

    Published: 18 Jan 2015
    5
    Medium

    CVE-2014-9638

    Last Modified: 12 Apr 2025

    oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.

    Published: 18 Jan 2015
    5
    Medium

    CVE-2014-9639

    Last Modified: 12 Apr 2025

    Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.

    Published: 18 Jan 2015
    2.1
    Low

    CVE-2015-1345

    Last Modified: 12 Apr 2025

    The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.

    Published: 18 Jan 2015
    7.8
    High

    CVE-2014-3018

    Last Modified: 12 Apr 2025

    IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to cause a denial of service (reboot) via a flood of IP packets.

    Published: 17 Jan 2015
    5
    Medium

    CVE-2014-3019

    Last Modified: 12 Apr 2025

    IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage-pool access via a TELNET session.

    Published: 17 Jan 2015
    3.5
    Low

    CVE-2014-3032

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 17 Jan 2015
    2.1
    Low

    CVE-2014-4835

    Last Modified: 12 Apr 2025

    IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.

    Published: 17 Jan 2015
    4.3
    Medium

    CVE-2014-6197

    Last Modified: 12 Apr 2025

    IBM Security Network Protection 5.1.x and 5.2.x before 5.2.0.0 FP5 and 5.3.x before 5.3.0.0 FP1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 17 Jan 2015
    5
    Medium

    CVE-2015-0590

    Last Modified: 12 Apr 2025

    Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a meeting-join action, aka Bug ID CSCuo34165.

    Published: 17 Jan 2015
    7.8
    High

    CVE-2015-0924

    Last Modified: 12 Apr 2025

    Ceragon FibeAir IP-10 bridges have a default password for the root account, which makes it easier for remote attackers to obtain access via a (1) HTTP, (2) SSH, (3) TELNET, or (4) CLI session.

    Published: 17 Jan 2015
    10
    Critical

    CVE-2014-5419

    Last Modified: 5 Nov 2025

    GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different customers' installations, which makes it easier for remote attackers to obtain the cleartext content of network traffic by reading this key from a firmware image and then sniffing the network.

    Published: 17 Jan 2015
    6.6
    Medium

    CVE-2014-2355

    Last Modified: 3 Oct 2025

    The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file.

    Published: 17 Jan 2015
    10
    Critical

    CVE-2014-9199

    Last Modified: 5 Sept 2025

    The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.

    Published: 17 Jan 2015
    5.4
    Medium

    CVE-2014-9194

    Last Modified: 29 Jul 2025

    Arbiter 1094B GPS Substation Clock allows remote attackers to cause a denial of service (disruption) via crafted radio transmissions that spoof GPS satellite broadcasts.

    Published: 17 Jan 2015
    10
    Critical

    CVE-2014-9195

    Last Modified: 5 Sept 2025

    Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.

    Published: 17 Jan 2015
    5
    Medium

    CVE-2014-5418

    Last Modified: 5 Nov 2025

    GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot) via crafted packets.

    Published: 17 Jan 2015
    7.5
    High

    CVE-2014-9603

    Last Modified: 12 Apr 2025

    The vmd_decode function in libavcodec/vmdvideo.c in FFmpeg before 2.5.2 does not validate the relationship between a certain length value and the frame width, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Sierra VMD video data.

    Published: 16 Jan 2015
    7.5
    High

    CVE-2014-9604

    Last Modified: 12 Apr 2025

    libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video data, related to the (1) restore_median and (2) restore_median_il functions.

    Published: 16 Jan 2015
    7.5
    High

    CVE-2014-9602

    Last Modified: 12 Apr 2025

    libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted X-Face image data.

    Published: 16 Jan 2015
    5
    Medium

    CVE-2014-9476

    Last Modified: 12 Apr 2025

    MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/."

    Published: 16 Jan 2015
    7.2
    High

    CVE-2014-1949

    Last Modified: 12 Apr 2025

    GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.

    Published: 16 Jan 2015
    7.1
    High

    CVE-2014-6382

    Last Modified: 12 Apr 2025

    The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2, when configured as a broadband edge (BBE) router, allows remote attackers to cause a denial of service (jpppd crash and restart) by sending a crafted PAP Authenticate-Request after the PPPoE Discovery and LCP phase are complete.

    Published: 16 Jan 2015
    5
    Medium

    CVE-2014-6383

    Last Modified: 12 Apr 2025

    The stateless firewall in Juniper Junos 13.3R3, 14.1R1, and 14.1R2, when using Trio-based PFE modules, does not properly match ports, which might allow remote attackers to bypass firewall rule.

    Published: 16 Jan 2015
    6.9
    Medium

    CVE-2014-6384

    Last Modified: 12 Apr 2025

    Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 does not properly handle double quotes in authorization attributes in the TACACS+ configuration, which allows local users to bypass the security policy and execute commands via unspecified vectors.

    Published: 16 Jan 2015
    6.1
    Medium

    CVE-2014-6385

    Last Modified: 12 Apr 2025

    Juniper Junos 11.4 before 11.4R13, 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, 12.2 before 12.2R9, 12.3R7 before 12.3R7-S1, 12.3 before 12.3R8, 13.1 before 13.1R5, 13.2 before 13.2R6, 13.3 before 13.3R4, 14.1 before 14.1R2, and 14.2 before 14.2R1 allows remote attackers to cause a denial of service (kernel crash and restart) via a crafted fragmented OSPFv3 packet with an IPsec Authentication Header (AH).

    Published: 16 Jan 2015
    7.8
    High

    CVE-2014-6386

    Last Modified: 12 Apr 2025

    Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R9, 12.3R2 before 12.3R2-S3, 12.3 before 12.3R3, 13.1 before 13.1R4, and 13.2 before 13.2R1 allows remote attackers to cause a denial of service (assertion failure and rpd restart) via a crafted BGP FlowSpec prefix.

    Published: 16 Jan 2015
    3.5
    Low

    CVE-2014-9475

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.19.23, 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote authenticated users to inject arbitrary web script or HTML via a wikitext message.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2014-9477

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Listings extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) url parameter.

    Published: 16 Jan 2015
    2.6
    Low

    CVE-2014-9478

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the preview in the ExpandTemplates extension for MediaWiki, when $wgRawHTML is set to true, allows remote attackers to inject arbitrary web script or HTML via the wpInput parameter to the Special:ExpandTemplates page.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2014-9479

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the preview in the TemplateSandbox extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via the text parameter to Special:TemplateSandbox.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2014-9480

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Hovercards extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors related to text extracts.

    Published: 16 Jan 2015
    6.5
    Medium

    CVE-2015-1029

    Last Modified: 12 Apr 2025

    The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to gain privileges or obtain sensitive information by prepopulating the fact cache.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2015-1058

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Category][title] parameter to admin/categories/add, (2) data[Field][title] parameter to admin/fields/ajax_fields/, (3) name property in a basicInfo JSON object to admin/tools/create_theme, (4) data[Link][link_title] parameter to admin/links/links/add, or (5) data[ForumTopic][subject] parameter to forums/off-topic/new.

    Published: 16 Jan 2015
    5.8
    Medium

    CVE-2015-1060

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.

    Published: 16 Jan 2015
    6.5
    Medium

    CVE-2015-1059

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in /app/webroot/uploads.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2015-1057

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary web script or HTML via the "Real Name" value.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2014-9599

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the filemanager in b2evolution before 5.2.1 allows remote attackers to inject arbitrary web script or HTML via the fm_filter parameter to blogs/admin.php.

    Published: 16 Jan 2015
    7.2
    High

    CVE-2014-9600

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Macroplant iExplorer 3.6.3.0 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse itunesmobiledevice.dll.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2015-1053

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administrative backend in Croogo before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to admin/file_manager/file_manager/editfile.

    Published: 16 Jan 2015
    3.5
    Low

    CVE-2015-1054

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Games feature in Crea8Social 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the Game Content field in Add Game.

    Published: 16 Jan 2015
    7.5
    High

    CVE-2015-1055

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/admin-ajax.php.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2015-1056

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Brother MFC-J4410DW printer with firmware before L allows remote attackers to inject arbitrary web script or HTML via the url parameter to general/status.html and possibly other pages.

    Published: 16 Jan 2015
    7.5
    High

    CVE-2015-0234

    Last Modified: 20 Apr 2025

    Multiple temporary file creation vulnerabilities in pki-core 10.2.0.

    Published: 16 Jan 2015
    5.5
    Medium

    CVE-2015-1573

    Last Modified: 12 Apr 2025

    The nft_flush_table function in net/netfilter/nf_tables_api.c in the Linux kernel before 3.18.5 mishandles the interaction between cross-chain jumps and ruleset flushes, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability.

    Published: 16 Jan 2015
    6.4
    Medium

    CVE-2015-2304

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.

    Published: 16 Jan 2015
    9.1
    Critical

    CVE-2014-8164

    Last Modified: 21 Nov 2024

    A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.

    Published: 16 Jan 2015
    5.5
    Medium

    CVE-2014-3536

    Last Modified: 21 Nov 2024

    CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration

    Published: 16 Jan 2015
    4
    Medium

    CVE-2014-9623

    Last Modified: 12 Apr 2025

    OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.

    Published: 16 Jan 2015