CVE Feed

    Dashboard / CVE

    4.2
    Medium

    CVE-2015-0233

    Last Modified: 20 Apr 2025

    Multiple insecure Temporary File vulnerabilities in 389 Administration Server before 1.1.38.

    Published: 16 Jan 2015
    Unknown

    CVE-2015-1160

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2015-1308

    Last Modified: 12 Apr 2025

    kde-workspace 4.2.0 and plasma-workspace before 5.1.95 allows remote attackers to obtain input events, and consequently obtain passwords, by leveraging access to the X server when the screen is locked.

    Published: 16 Jan 2015
    4.3
    Medium

    CVE-2014-9596

    Last Modified: 12 Apr 2025

    Panasonic Arbitrator Back-End Server (BES) MK 2.0 VPU before 9.3.1 build 4.08.003.0, when USB Wi-Fi or Direct LAN is enabled, and MK 3.0 VPU before 9.3.1 build 5.06.000.0, when Embedded Wi-Fi or Direct LAN is enabled, does not use encryption, which allows remote attackers to obtain sensitive information by sniffing the network for client-server traffic, as demonstrated by Active Directory credential information.

    Published: 15 Jan 2015
    5
    Medium

    CVE-2015-0591

    Last Modified: 12 Apr 2025

    Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to cause a denial of service (daemon hang and GUI outage) via a flood of malformed TCP packets, aka Bug ID CSCur44177.

    Published: 15 Jan 2015
    6.8
    Medium

    CVE-2015-0588

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuo77055.

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2014-7881

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the server in HP Insight Control allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2014-8022

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Identity Services Engine allow remote attackers to inject arbitrary web script or HTML via input to unspecified web pages, aka Bug IDs CSCur69835 and CSCur69776.

    Published: 15 Jan 2015
    5
    Medium

    CVE-2014-8034

    Last Modified: 12 Apr 2025

    Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.

    Published: 15 Jan 2015
    7.2
    High

    CVE-2014-8904

    Last Modified: 12 Apr 2025

    lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2014-9570

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the MyWebsiteAdvisor Simple Security plugin 1.1.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) datefilter parameter in the access_log page to wp-admin/users.php or (2) simple_security_ip_blacklist[] parameter in an add_blacklist_ip action in the ip_blacklist page to wp-admin/users.php.

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2015-1039

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in user/login.phtml in ZF-Commons ZfcUser before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.

    Published: 15 Jan 2015
    3.5
    Low

    CVE-2015-1040

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in BEdita 3.4.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lrealname field in the editProfile form to index.php/home/profile; the (2) data[title] or (3) data[description] field in the addQuickItem form to index.php; the (4) "note text" field in the saveNote form to index.php/areas; or the (5) titleBEObject or (6) tagsArea field in the updateForm form to index.php/documents/view.

    Published: 15 Jan 2015
    5.8
    Medium

    CVE-2015-1051

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

    Published: 15 Jan 2015
    7.5
    High

    CVE-2014-9560

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to execute arbitrary SQL commands via the post parameter.

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2014-9561

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in redir_last_post_list.php in SoftBB 0.1.3 allows remote attackers to inject arbitrary web script or HTML via the post parameter.

    Published: 15 Jan 2015
    6.8
    Medium

    CVE-2014-7957

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Pods plugin before 2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the toggled parameter in a toggle action in the pods-components page to wp-admin/admin.php, (2) delete a pod in a delete action in the pods page to wp-admin/admin.php, (3) reset pod settings and data via the pods_reset parameter in the pod-settings page to wp-admin/admin.php, (4) deactivate and reset pod data via the pods_reset_deactivate parameter in the pod-settings page to wp-admin/admin.php, (5) delete the admin role via the id parameter in a delete action in the pods-component-roles-and-capabilities page to wp-admin/admin.php, or (6) enable "roles and capabilities" in a toggle action in the pods-components page to wp-admin/admin.php.

    Published: 15 Jan 2015
    4.6
    Medium

    CVE-2014-8394

    Last Modified: 12 Apr 2025

    Multiple untrusted search path vulnerabilities in Corel CAD 2014 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) FxManagedCommands_3.08_9.tx or (2) TD_Mgd_3.08_9.dll file in the current working directory.

    Published: 15 Jan 2015
    6.5
    Medium

    CVE-2014-9308

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in products/banners/.

    Published: 15 Jan 2015
    5
    Medium

    CVE-2014-9593

    Last Modified: 12 Apr 2025

    Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

    Published: 15 Jan 2015
    6.5
    Medium

    CVE-2014-9595

    Last Modified: 12 Apr 2025

    Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, related to the Spool System, aka SAP Note 2061271.

    Published: 15 Jan 2015
    6.4
    Medium

    CVE-2015-0552

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the gcab_folder_extract function in libgcab/gcab-folder.c in gcab 0.4 allows remote attackers to write to arbitrary files via crafted path in a CAB file, as demonstrated by "\tmp\moo."

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2015-1050

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in F5 BIG-IP Application Security Manager (ASM) before 11.6 allows remote attackers to inject arbitrary web script or HTML via the Response Body field when creating a new user account.

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2014-7956

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Pods plugin before 2.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter in an edit action in the pods page to wp-admin/admin.php.

    Published: 15 Jan 2015
    4.6
    Medium

    CVE-2014-8395

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Corel Painter 2015 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wacommt.dll file that is located in the same folder as the file being processed.

    Published: 15 Jan 2015
    4.6
    Medium

    CVE-2014-8396

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Corel PDF Fusion allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll file that is located in the same folder as the file being processed.

    Published: 15 Jan 2015
    4.6
    Medium

    CVE-2014-8397

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Corel VideoStudio PRO X7 or FastFlick allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse u32ZLib.dll file that is located in the same folder as the file being processed.

    Published: 15 Jan 2015
    4.6
    Medium

    CVE-2014-8398

    Last Modified: 12 Apr 2025

    Multiple untrusted search path vulnerabilities in Corel FastFlick allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) igfxcmrt32.dll, (2) ipl.dll, (3) MSPStyleLib.dll, (4) uFioUtil.dll, (5) uhDSPlay.dll, (6) uipl.dll, (7) uvipl.dll, (8) VC1DecDll.dll, or (9) VC1DecDll_SSE3.dll file that is located in the same folder as the file being processed.

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2014-8869

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin 1.x before 1.1.2 for Woltlab Burning Board 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) app_android_id or (2) app_kindle_url parameter.

    Published: 15 Jan 2015
    5.8
    Medium

    CVE-2014-8870

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin before 1.1.2 for Woltlab Burning Board 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the board_url parameter.

    Published: 15 Jan 2015
    6.5
    Medium

    CVE-2014-9594

    Last Modified: 12 Apr 2025

    Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vectors, related to the ABAP VM, aka SAP Note 2059734.

    Published: 15 Jan 2015
    6.8
    Medium

    CVE-2014-9587

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Roundcube Webmail before 1.0.4 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to (1) address book operations or the (2) ACL or (3) Managesieve plugins.

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2015-1041

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path in the QUERY_STRING.

    Published: 15 Jan 2015
    4.3
    Medium

    CVE-2015-1052

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web script or HTML via the result parameter to upload_files/pk/include.php.

    Published: 15 Jan 2015
    8.5
    High

    CVE-2014-8143

    Last Modified: 12 Apr 2025

    Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.

    Published: 15 Jan 2015
    5
    Medium

    CVE-2015-0583

    Last Modified: 12 Apr 2025

    Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors related to file: URIs, aka Bug ID CSCus18281.

    Published: 14 Jan 2015
    5
    Medium

    CVE-2014-3314

    Last Modified: 12 Apr 2025

    Cisco AnyConnect on Android and OS X does not properly verify the host type, which allows remote attackers to spoof authentication forms and possibly capture credentials via unspecified vectors, aka Bug IDs CSCuo24931 and CSCuo24940.

    Published: 14 Jan 2015
    4.3
    Medium

    CVE-2015-0577

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the IronPort Spam Quarantine (ISQ) page in Cisco AsyncOS, as used on the Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA), allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCus22925 and CSCup08113.

    Published: 14 Jan 2015
    5.7
    Medium

    CVE-2015-0578

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software, when a DHCPv6 relay is configured, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets on the local network, aka Bug ID CSCur45455.

    Published: 14 Jan 2015
    5
    Medium

    CVE-2015-0579

    Last Modified: 12 Apr 2025

    Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway allow remote attackers to cause a denial of service (memory and CPU consumption, and partial outage) via crafted SIP packets, aka Bug ID CSCur12473.

    Published: 14 Jan 2015
    5
    Medium

    CVE-2014-8637

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.

    Published: 14 Jan 2015
    2.1
    Low

    CVE-2014-5231

    Last Modified: 12 Apr 2025

    The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to extract the password from storage via unspecified vectors.

    Published: 14 Jan 2015
    1.9
    Low

    CVE-2014-5232

    Last Modified: 12 Apr 2025

    The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows local users to bypass an intended application-password requirement by leveraging the running of the app in the background state.

    Published: 14 Jan 2015
    1.9
    Low

    CVE-2014-5233

    Last Modified: 12 Apr 2025

    The Siemens SIMATIC WinCC Sm@rtClient app before 1.0.2 for iOS allows physically proximate attackers to discover Sm@rtServer credentials by leveraging an error in the credential-processing mechanism.

    Published: 14 Jan 2015
    5
    Medium

    CVE-2014-8640

    Last Modified: 12 Apr 2025

    The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers to cause a denial of service (uninitialized-memory read and application crash) via crafted API calls.

    Published: 14 Jan 2015
    4.3
    Medium

    CVE-2014-8642

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.

    Published: 14 Jan 2015
    7.5
    High

    CVE-2014-8635

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 14 Jan 2015
    7.1
    High

    CVE-2014-8643

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.

    Published: 14 Jan 2015
    6.5
    Medium

    CVE-2014-7814

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL commands via a crafted REST API request to an SQL filter.

    Published: 14 Jan 2015
    4.7
    Medium

    CVE-2015-0011

    Last Modified: 12 Apr 2025

    mrxdav.sys (aka the WebDAV driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to bypass an impersonation protection mechanism, and obtain privileges for redirection of WebDAV requests, via a crafted application, aka "WebDAV Elevation of Privilege Vulnerability."

    Published: 13 Jan 2015