CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2014-8500

    Last Modified: 12 Apr 2025

    ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.

    Published: 8 Dec 2014
    4.4
    Medium

    CVE-2014-9065

    Last Modified: 12 Apr 2025

    common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability to CVE-2014-9066.

    Published: 8 Dec 2014
    6.8
    Medium

    CVE-2014-9300

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition before 5.0.a allows remote attackers to hijack the authentication of users for requests that access unauthorized URLs and obtain user credentials via a URL in the url parameter.

    Published: 7 Dec 2014
    7.8
    High

    CVE-2014-8868

    Last Modified: 12 Apr 2025

    EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username and password, and possibly other sensitive information, via a request to /4.

    Published: 7 Dec 2014
    6.4
    Medium

    CVE-2014-9301

    Last Modified: 12 Apr 2025

    Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger outbound requests to intranet servers, conduct port scans, and read arbitrary files via a crafted URI in the endpoint parameter.

    Published: 7 Dec 2014
    5
    Medium

    CVE-2014-9302

    Last Modified: 12 Apr 2025

    Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attackers to trigger outbound requests via a crafted URI in the url parameter.

    Published: 7 Dec 2014
    7.8
    High

    CVE-2014-9303

    Last Modified: 12 Apr 2025

    EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or A through D, different vectors than CVE-2014-8868.

    Published: 7 Dec 2014
    7.5
    High

    CVE-2014-9304

    Last Modified: 12 Apr 2025

    Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

    Published: 7 Dec 2014
    6.5
    Medium

    CVE-2014-8127

    Last Modified: 20 Apr 2025

    LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.

    Published: 7 Dec 2014
    6.5
    Medium

    CVE-2014-8128

    Last Modified: 21 Nov 2024

    LibTIFF prior to 4.0.4, as used in Apple iOS before 8.4 and OS X before 10.10.4 and other products, allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image.

    Published: 7 Dec 2014
    6.5
    Medium

    CVE-2014-8130

    Last Modified: 21 Nov 2024

    The _TIFFmalloc function in tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c, as demonstrated by tiffdither.

    Published: 7 Dec 2014
    8.8
    High

    CVE-2014-8129

    Last Modified: 21 Nov 2024

    LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by failure of tif_next.c to verify that the BitsPerSample value is 2, and the t2p_sample_lab_signed_to_unsigned function in tiff2pdf.c.

    Published: 7 Dec 2014
    5
    Medium

    CVE-2014-9117

    Last Modified: 12 Apr 2025

    MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging knowledge of a CAPTCHA answer for a public_key parameter value, as demonstrated by E4652 for the public_key value 0.

    Published: 6 Dec 2014
    9.3
    Critical

    CVE-2014-6140

    Last Modified: 12 Apr 2025

    IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2) Self-service portal, (3) Trusted Services provider, or (4) Admin Portal.

    Published: 6 Dec 2014
    9
    Critical

    CVE-2014-4629

    Last Modified: 12 Apr 2025

    EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read or delete arbitrary files via unspecified vectors related to an insecure direct object reference.

    Published: 6 Dec 2014
    5
    Medium

    CVE-2014-5429

    Last Modified: 12 Apr 2025

    DNP Master Driver 3.02 and earlier in Elipse SCADA 2.29 build 141 and earlier, E3 1.0 through 4.6, and Elipse Power 1.0 through 4.6 allows remote attackers to cause a denial of service (CPU consumption) via malformed packets.

    Published: 6 Dec 2014
    2.1
    Low

    CVE-2014-3099

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Security component in IBM Systems Director 6.3.0 through 6.3.5 allows local users to obtain sensitive information via unknown vectors.

    Published: 6 Dec 2014
    3.2
    Low

    CVE-2014-7251

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.

    Published: 6 Dec 2014
    3.5
    Low

    CVE-2014-5353

    Last Modified: 12 Apr 2025

    The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password policy.

    Published: 6 Dec 2014
    5.8
    Medium

    CVE-2014-9292

    Last Modified: 12 Apr 2025

    Server-side request forgery (SSRF) vulnerability in proxy.php in the jRSS Widget plugin 1.2 and earlier for WordPress allows remote attackers to trigger outbound requests and enumerate open ports via the url parameter.

    Published: 5 Dec 2014
    10
    Critical

    CVE-2014-8877

    Last Modified: 12 Apr 2025

    The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.

    Published: 5 Dec 2014
    4.6
    Medium

    CVE-2014-7252

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary code or read kernel memory via unknown vectors related to userland data and "improper data validation."

    Published: 5 Dec 2014
    7.5
    High

    CVE-2014-7255

    Last Modified: 12 Apr 2025

    Internet Initiative Japan Inc. SEIL Series routers SEIL/X1 2.50 through 4.62, SEIL/X2 2.50 through 4.62, SEIL/B1 2.50 through 4.62, and SEIL/x86 Fuji 1.70 through 3.22 allow remote attackers to cause a denial of service (CPU and traffic consumption) via a large number of NTP requests within a short time, which causes unnecessary NTP responses to be sent.

    Published: 5 Dec 2014
    7.8
    High

    CVE-2014-7256

    Last Modified: 12 Apr 2025

    The (1) PPP Access Concentrator (PPPAC) and (2) Dial-Up Networking Internet Initiative Japan Inc. SEIL series routers SEIL/x86 Fuji 1.00 through 3.22; SEIL/X1, SEIL/X2, and SEIL/B1 1.00 through 4.62; SEIL/Turbo 1.82 through 2.18; and SEIL/neu 2FE Plus 1.82 through 2.18 allow remote attackers to cause a denial of service (restart) via crafted (a) GRE or (b) MPPE packets.

    Published: 5 Dec 2014
    4.6
    Medium

    CVE-2014-7254

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in ARROWS Me F-11D allows physically proximate attackers to read or modify flash memory via unknown vectors.

    Published: 5 Dec 2014
    5
    Medium

    CVE-2014-7243

    Last Modified: 12 Apr 2025

    LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 5 Dec 2014
    7.2
    High

    CVE-2014-7253

    Last Modified: 12 Apr 2025

    FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute arbitrary commands via unspecified vectors.

    Published: 5 Dec 2014
    4.3
    Medium

    CVE-2014-7258

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB Clip Board 2.91 and earlier, when running certain versions of Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2014
    5
    Medium

    CVE-2014-7259

    Last Modified: 12 Apr 2025

    SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain privileges via a crafted application.

    Published: 5 Dec 2014
    7.2
    High

    CVE-2014-2273

    Last Modified: 12 Apr 2025

    The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary memory locations via unspecified vectors.

    Published: 5 Dec 2014
    5
    Medium

    CVE-2014-8123

    Last Modified: 12 Apr 2025

    Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.

    Published: 5 Dec 2014
    7.5
    High

    CVE-2014-8990

    Last Modified: 12 Apr 2025

    default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.

    Published: 5 Dec 2014
    4.3
    Medium

    CVE-2014-9142

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script or HTML via the failrefer parameter.

    Published: 5 Dec 2014
    7.5
    High

    CVE-2014-3996

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to LinkViewFetchServlet.dat.

    Published: 5 Dec 2014
    7.5
    High

    CVE-2014-3997

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 10.3.3 build 10330, and possibly other ManageEngine products, allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the sv parameter to MetadataServlet.dat.

    Published: 5 Dec 2014
    4.3
    Medium

    CVE-2014-8800

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fb_login_button parameter in a newfb_update_options action.

    Published: 5 Dec 2014
    6.8
    Medium

    CVE-2014-9129

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.

    Published: 5 Dec 2014
    4.3
    Medium

    CVE-2014-9143

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the failrefer parameter.

    Published: 5 Dec 2014
    7.5
    High

    CVE-2014-9144

    Last Modified: 12 Apr 2025

    Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (setobject_ip parameter).

    Published: 5 Dec 2014
    4.3
    Medium

    CVE-2014-9212

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Altitude uAgent in Altitude uCI (Unified Customer Interaction) 7.5 allow remote attackers to inject arbitrary web script or HTML via (1) an email hyperlink or the (2) style parameter in the image attribute section.

    Published: 5 Dec 2014
    7.5
    High

    CVE-2014-9215

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to execute arbitrary SQL commands via the email parameter in the register page to index.php. NOTE: the email parameter in the forget page vector is already covered by CVE-2012-4034.2.

    Published: 5 Dec 2014
    7.5
    High

    CVE-2014-9705

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

    Published: 5 Dec 2014
    4
    Medium

    CVE-2014-8131

    Last Modified: 12 Apr 2025

    The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated users to cause a denial of service (deadlock or segmentation fault and crash) via a request to access the users does not have privileges to access.

    Published: 5 Dec 2014
    3.3
    Low

    CVE-2014-8134

    Last Modified: 12 Apr 2025

    The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value.

    Published: 5 Dec 2014
    9.8
    Critical

    CVE-2014-9515

    Last Modified: 20 Apr 2025

    Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.

    Published: 5 Dec 2014
    5
    Medium

    CVE-2014-6034

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8 through 11.3, Social IT Plus 11.0, and IT360 10.4 and earlier allows remote attackers or remote authenticated users to write to and execute arbitrary WAR files via a .. (dot dot) in the regionID parameter.

    Published: 4 Dec 2014
    6.4
    Medium

    CVE-2014-6036

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the fileName parameter.

    Published: 4 Dec 2014
    7.5
    High

    CVE-2014-7867

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allows remote attackers or remote authenticated users to execute arbitrary SQL commands via the probeName parameter.

    Published: 4 Dec 2014
    7.5
    High

    CVE-2014-7868

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) OPM_BVNAME parameter in a Delete operation to the APMBVHandler servlet or (2) query parameter in a compare operation to the DataComparisonServlet servlet.

    Published: 4 Dec 2014
    5
    Medium

    CVE-2014-5445

    Last Modified: 12 Apr 2025

    Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1) CSVServlet or (2) CReportPDFServlet servlet.

    Published: 4 Dec 2014