CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2014-4475

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.2.1, 7.x before 7.1.1, and 8.x before 8.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-12-2-1.

    Published: 10 Dec 2014
    7.2
    High

    CVE-2014-8003

    Last Modified: 12 Apr 2025

    Cisco Integrated Management Controller in Cisco Unified Computing System 2.2(2c)A and earlier allows local users to obtain shell access via a crafted map-nfs command, aka Bug ID CSCup05998.

    Published: 10 Dec 2014
    5
    Medium

    CVE-2014-8009

    Last Modified: 12 Apr 2025

    The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log files, aka Bug ID CSCur99239.

    Published: 10 Dec 2014
    6.5
    Medium

    CVE-2014-8010

    Last Modified: 12 Apr 2025

    The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205.

    Published: 10 Dec 2014
    5
    Medium

    CVE-2014-8451

    Last Modified: 12 Apr 2025

    An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2014-8448.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8446

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-8445, CVE-2014-8447, CVE-2014-8456, CVE-2014-8458, CVE-2014-8459, CVE-2014-8461, and CVE-2014-9158.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8447

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-8445, CVE-2014-8446, CVE-2014-8456, CVE-2014-8458, CVE-2014-8459, CVE-2014-8461, and CVE-2014-9158.

    Published: 10 Dec 2014
    5
    Medium

    CVE-2014-8448

    Last Modified: 12 Apr 2025

    An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain sensitive information via unknown vectors, a different vulnerability than CVE-2014-8451.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8449

    Last Modified: 12 Apr 2025

    Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.

    Published: 10 Dec 2014
    5
    Medium

    CVE-2014-8453

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8454

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8455 and CVE-2014-9165.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8455

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8454 and CVE-2014-9165.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8456

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-8445, CVE-2014-8446, CVE-2014-8447, CVE-2014-8458, CVE-2014-8459, CVE-2014-8461, and CVE-2014-9158.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8457

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8460 and CVE-2014-9159.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8458

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-8445, CVE-2014-8446, CVE-2014-8447, CVE-2014-8456, CVE-2014-8459, CVE-2014-8461, and CVE-2014-9158.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8461

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-8445, CVE-2014-8446, CVE-2014-8447, CVE-2014-8456, CVE-2014-8458, CVE-2014-8459, and CVE-2014-9158.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-9158

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-8445, CVE-2014-8446, CVE-2014-8447, CVE-2014-8456, CVE-2014-8458, CVE-2014-8459, and CVE-2014-8461.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-9159

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8457 and CVE-2014-8460.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-9165

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8454 and CVE-2014-8455.

    Published: 10 Dec 2014
    5
    Medium

    CVE-2014-9166

    Last Modified: 12 Apr 2025

    Adobe ColdFusion 10 before Update 15 and 11 before Update 3 allows attackers to cause a denial of service (resource consumption) via unspecified vectors.

    Published: 10 Dec 2014
    5.5
    Medium

    CVE-2014-9363

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.

    Published: 10 Dec 2014
    4.3
    Medium

    CVE-2014-9364

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Unified Login form in the LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Dec 2014
    4.3
    Medium

    CVE-2014-9361

    Last Modified: 12 Apr 2025

    The LoginToboggan module 7.x-1.x before 7.x-1.4 for Drupal does not properly unset the authorized user role for certain users, which allows remote attackers with the pre-authorized role to gain privileges and possibly obtain sensitive information by accessing a Page Not Found (404) page.

    Published: 10 Dec 2014
    3.5
    Low

    CVE-2014-9362

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the path-based meta tag editing form in the Meta tags quick module 7.x-2.x before 7.x-2.8 for Drupal allows remote authenticated users with the "Edit path based meta tags" permission to inject arbitrary web script or HTML via vectors related to deleting a Path-based Metatag.

    Published: 10 Dec 2014
    7.5
    High

    CVE-2014-7866

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. (dot dot) in the (1) fileName parameter to the MigrateLEEData servlet or (2) zipFileName parameter in a downloadFileFromProbe operation to the MigrateCentralData servlet.

    Published: 10 Dec 2014
    7.5
    High

    CVE-2014-8298

    Last Modified: 12 Apr 2025

    The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.

    Published: 10 Dec 2014
    5
    Medium

    CVE-2014-7807

    Last Modified: 12 Apr 2025

    Apache CloudStack 4.3.x before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to bypass authentication via a login request without a password, which triggers an unauthenticated bind.

    Published: 10 Dec 2014
    4.6
    Medium

    CVE-2014-9091

    Last Modified: 12 Apr 2025

    Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.

    Published: 10 Dec 2014
    5
    Medium

    CVE-2014-8601

    Last Modified: 12 Apr 2025

    PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezdns.it.

    Published: 10 Dec 2014
    4.3
    Medium

    CVE-2014-9120

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Subrion CMS before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to subrion/search/.

    Published: 10 Dec 2014
    6.4
    Medium

    CVE-2014-9360

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in Scalix Web Access 11.4.6.12377 and 12.2.0.14697 allows remote attackers to read arbitrary files and trigger requests to intranet servers via a crafted request.

    Published: 10 Dec 2014
    4.3
    Medium

    CVE-2014-8488

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the Shorten functionality.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-8496

    Last Modified: 12 Apr 2025

    Digicom DG-5514T ADSL router with firmware 3.2 generates predictable session IDs, which allows remote attackers to gain administrator privileges via a brute force session hijacking attack.

    Published: 10 Dec 2014
    10
    Critical

    CVE-2014-9162

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to obtain sensitive information via unspecified vectors.

    Published: 10 Dec 2014
    4.3
    Medium

    CVE-2014-9352

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the mail administration login panel in Scalix Web Access 11.4.6.12377 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Dec 2014
    6.4
    Medium

    CVE-2014-9351

    Last Modified: 12 Apr 2025

    engine/server/server.cpp in Teeworlds 0.6.x before 0.6.3 allows remote attackers to read memory and cause a denial of service (crash) via unspecified vectors.

    Published: 9 Dec 2014
    7.5
    High

    CVE-2014-9275

    Last Modified: 12 Apr 2025

    UnRTF allows remote attackers to cause a denial of service (out-of-bounds memory access and crash) and possibly execute arbitrary code via a crafted RTF file.

    Published: 9 Dec 2014
    7.5
    High

    CVE-2014-9274

    Last Modified: 12 Apr 2025

    UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999".

    Published: 9 Dec 2014
    4.3
    Medium

    CVE-2014-9281

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/copy_field.php in MantisBT before 1.2.18 allows remote attackers to inject arbitrary web script or HTML via the dest_id field.

    Published: 9 Dec 2014
    7.5
    High

    CVE-2014-9316

    Last Modified: 12 Apr 2025

    The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via vectors related to LJIF tags in an MJPEG file.

    Published: 9 Dec 2014
    7.5
    High

    CVE-2014-9317

    Last Modified: 12 Apr 2025

    The decode_ihdr_chunk function in libavcodec/pngdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via an IDAT before an IHDR in a PNG file.

    Published: 9 Dec 2014
    7.5
    High

    CVE-2014-9318

    Last Modified: 12 Apr 2025

    The raw_decode function in libavcodec/rawdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds heap access) and possibly have other unspecified impact via a crafted .cine file that triggers the avpicture_get_size function to return a negative frame size.

    Published: 9 Dec 2014
    5
    Medium

    CVE-2014-9319

    Last Modified: 12 Apr 2025

    The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted .bit file.

    Published: 9 Dec 2014
    7.8
    High

    CVE-2014-9163

    Last Modified: 21 Apr 2026

    Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.

    Published: 9 Dec 2014
    10
    Critical

    CVE-2014-0580

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 9 Dec 2014
    5
    Medium

    CVE-2014-5355

    Last Modified: 12 Apr 2025

    MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a '\0' character, which allows remote attackers to (1) cause a denial of service (NULL pointer dereference) via a zero-byte version string or (2) cause a denial of service (out-of-bounds read) by omitting the '\0' character, related to appl/user_user/server.c and lib/krb5/krb/recvauth.c.

    Published: 9 Dec 2014
    6.5
    Medium

    CVE-2014-8095

    Last Modified: 29 Aug 2025

    The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1) SProcXChangeDeviceControl, (2) ProcXChangeDeviceControl, (3) ProcXChangeFeedbackControl, (4) ProcXSendExtensionEvent, (5) SProcXIAllowEvents, (6) SProcXIChangeCursor, (7) ProcXIChangeHierarchy, (8) SProcXIGetClientPointer, (9) SProcXIGrabDevice, (10) SProcXIUngrabDevice, (11) ProcXIUngrabDevice, (12) SProcXIPassiveGrabDevice, (13) ProcXIPassiveGrabDevice, (14) SProcXIPassiveUngrabDevice, (15) ProcXIPassiveUngrabDevice, (16) SProcXListDeviceProperties, (17) SProcXDeleteDeviceProperty, (18) SProcXIListProperties, (19) SProcXIDeleteProperty, (20) SProcXIGetProperty, (21) SProcXIQueryDevice, (22) SProcXIQueryPointer, (23) SProcXISelectEvents, (24) SProcXISetClientPointer, (25) SProcXISetFocus, (26) SProcXIGetFocus, or (27) SProcXIWarpPointer function.

    Published: 9 Dec 2014
    10
    Critical

    CVE-2014-8443

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors.

    Published: 9 Dec 2014
    10
    Critical

    CVE-2014-0587

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-9164.

    Published: 9 Dec 2014
    4.3
    Medium

    CVE-2014-7852

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in JBoss RichFaces, as used in JBoss Portal 6.1.1, allows remote attackers to inject arbitrary web script or HTML via crafted URL, which is not properly handled in a CSS file.

    Published: 9 Dec 2014