CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2013-6494

    Last Modified: 12 Apr 2025

    fedup 0.9.0 in Fedora 19, 20, and 21 uses a temporary directory with a static name for its download cache, which allows local users to cause a denial of service (prevention of system updates).

    Published: 2 Dec 2014
    6
    Medium

    CVE-2014-8791

    Last Modified: 12 Apr 2025

    project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.

    Published: 2 Dec 2014
    7.2
    High

    CVE-2014-5284

    Last Modified: 12 Apr 2025

    host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts.deny and gain root privileges by creating the temporary files before automatic IP blocking is performed.

    Published: 2 Dec 2014
    6.8
    Medium

    CVE-2014-1593

    Last Modified: 25 Nov 2025

    Stack-based buffer overflow in the mozilla::FileBlockCache::Read function in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execute arbitrary code via crafted media content.

    Published: 2 Dec 2014
    4.3
    Medium

    CVE-2014-1590

    Last Modified: 25 Nov 2025

    The XMLHttpRequest.prototype.send method in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to cause a denial of service (application crash) via a crafted JavaScript object.

    Published: 2 Dec 2014
    6.8
    Medium

    CVE-2014-1587

    Last Modified: 25 Nov 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 2 Dec 2014
    2.1
    Low

    CVE-2014-3561

    Last Modified: 12 Apr 2025

    The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.

    Published: 2 Dec 2014
    6.8
    Medium

    CVE-2014-1588

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 2 Dec 2014
    6.8
    Medium

    CVE-2014-1589

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypass intended access restrictions via an XBL binding.

    Published: 2 Dec 2014
    4.3
    Medium

    CVE-2014-1591

    Last Modified: 12 Apr 2025

    Mozilla Firefox 33.0 and SeaMonkey before 2.31 include path strings in CSP violation reports, which allows remote attackers to obtain sensitive information via a web site that receives a report after a redirect.

    Published: 2 Dec 2014
    6.8
    Medium

    CVE-2014-1592

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the nsHtml5TreeOperation function in xul.dll in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 allows remote attackers to execute arbitrary code by adding a second root element to an HTML5 document during parsing.

    Published: 2 Dec 2014
    6.8
    Medium

    CVE-2014-1594

    Last Modified: 25 Nov 2025

    Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird before 31.3, and SeaMonkey before 2.31 might allow remote attackers to execute arbitrary code by leveraging an incorrect cast from the BasicThebesLayer data type to the BasicContainerLayer data type.

    Published: 2 Dec 2014
    5.8
    Medium

    CVE-2014-5268

    Last Modified: 12 Apr 2025

    The Fasttoggle module 7.x-1.3 and 7.x-1.4 for Drupal allows remote attackers to block or unblock an account via a crafted user status link.

    Published: 1 Dec 2014
    7.5
    High

    CVE-2014-9151

    Last Modified: 12 Apr 2025

    The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.

    Published: 1 Dec 2014
    7.5
    High

    CVE-2014-9152

    Last Modified: 12 Apr 2025

    The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote attackers to guess the password via a brute force attack.

    Published: 1 Dec 2014
    4.3
    Medium

    CVE-2014-9153

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Services module 7.x-3.x before 7.x-3.10 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the callback parameter in a JSONP response.

    Published: 1 Dec 2014
    4
    Medium

    CVE-2014-9154

    Last Modified: 12 Apr 2025

    The Notify module 7.x-1.x before 7.x-1.1 for Drupal does not properly restrict access to (1) new or (2) modified nodes or (3) their fields, which allows remote authenticated users to obtain node titles, teasers, and fields by reading a notification email.

    Published: 1 Dec 2014
    4
    Medium

    CVE-2014-9155

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel.

    Published: 1 Dec 2014
    4
    Medium

    CVE-2014-9156

    Last Modified: 12 Apr 2025

    The FileField module 6.x-3.x before 6.x-3.13 for Drupal does not properly check permissions to view files, which allows remote authenticated users with permission to create or edit content to read private files by attaching an uploaded file.

    Published: 1 Dec 2014
    5
    Medium

    CVE-2014-9050

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the cli_scanpe function in libclamav/pe.c in ClamAV before 0.98.5 allows remote attackers to cause a denial of service (crash) via a crafted y0da Crypter PE file.

    Published: 1 Dec 2014
    2.1
    Low

    CVE-2013-6497

    Last Modified: 12 Apr 2025

    clamscan in ClamAV before 0.98.5, when using -a option, allows remote attackers to cause a denial of service (crash) as demonstrated by the jwplayer.js file.

    Published: 1 Dec 2014
    5
    Medium

    CVE-2014-2232

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 1 Dec 2014
    5
    Medium

    CVE-2014-2233

    Last Modified: 12 Apr 2025

    Server-side request forgery (SSRF) vulnerability in the MapAPI in Infoware MapSuite before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to trigger requests to intranet servers via unspecified vectors.

    Published: 1 Dec 2014
    4.3
    Medium

    CVE-2014-5237

    Last Modified: 12 Apr 2025

    Server-side request forgery (SSRF) vulnerability in the documentconverter component in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allows remote attackers to trigger requests to arbitrary servers and embed arbitrary images via a URL in an embedded image in a Text document, which is not properly handled by the image preview.

    Published: 1 Dec 2014
    4.3
    Medium

    CVE-2014-7291

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in api_events.php in Springshare LibCal 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) m or (2) cid parameter.

    Published: 1 Dec 2014
    5
    Medium

    CVE-2014-8749

    Last Modified: 12 Apr 2025

    Server-side request forgery (SSRF) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to trigger outbound requests that authenticate to arbitrary databases via the dbhost parameter.

    Published: 1 Dec 2014
    7.5
    High

    CVE-2014-1569

    Last Modified: 12 Apr 2025

    The definite_length_decoder function in lib/util/quickder.c in Mozilla Network Security Services (NSS) before 3.16.2.4 and 3.17.x before 3.17.3 does not ensure that the DER encoding of an ASN.1 length is properly formed, which allows remote attackers to conduct data-smuggling attacks by using a long byte sequence for an encoding, as demonstrated by the SEC_QuickDERDecodeItem function's improper handling of an arbitrary-length encoding of 0x00.

    Published: 1 Dec 2014
    4.3
    Medium

    CVE-2014-8958

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database, (2) table, or (3) column name that is improperly handled during rendering of the table browse page; a crafted ENUM value that is improperly handled during rendering of the (4) table print view or (5) zoom search page; or (6) a crafted pma_fontsize cookie that is improperly handled during rendering of the home page.

    Published: 30 Nov 2014
    6.5
    Medium

    CVE-2014-8959

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allows remote authenticated users to include and execute arbitrary local files via a crafted geometry-type parameter.

    Published: 30 Nov 2014
    3.5
    Low

    CVE-2014-8960

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename.

    Published: 30 Nov 2014
    4
    Medium

    CVE-2014-8961

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file's line count via a crafted parameter.

    Published: 30 Nov 2014
    6.4
    Medium

    CVE-2014-9150

    Last Modified: 12 Apr 2025

    Race condition in the MoveFileEx call hook feature in Adobe Reader and Acrobat 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently write to files in arbitrary locations, via an NTFS junction attack, a similar issue to CVE-2014-0568.

    Published: 30 Nov 2014
    6.8
    Medium

    CVE-2014-8429

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts via a crafted request to the owner/users page.

    Published: 28 Nov 2014
    3.6
    Low

    CVE-2014-8994

    Last Modified: 12 Apr 2025

    The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).

    Published: 28 Nov 2014
    9.3
    Critical

    CVE-2014-7178

    Last Modified: 12 Apr 2025

    Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.

    Published: 28 Nov 2014
    10
    Critical

    CVE-2014-8423

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.

    Published: 28 Nov 2014
    7.8
    High

    CVE-2014-8424

    Last Modified: 12 Apr 2025

    ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.

    Published: 28 Nov 2014
    7.8
    High

    CVE-2014-8425

    Last Modified: 12 Apr 2025

    The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.

    Published: 28 Nov 2014
    5
    Medium

    CVE-2014-8799

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.

    Published: 28 Nov 2014
    5
    Medium

    CVE-2014-8801

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the QUERY_STRING in a getfile action to wp-admin/admin-ajax.php.

    Published: 28 Nov 2014
    7.5
    High

    CVE-2014-9089

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in view_all_bug_page.php in MantisBT before 1.2.18 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to view_all_set.php.

    Published: 28 Nov 2014
    6.8
    Medium

    CVE-2014-4829

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 28 Nov 2014
    4.3
    Medium

    CVE-2014-4883

    Last Modified: 12 Apr 2025

    resolv.c in the DNS resolver in uIP, and dns.c in the DNS resolver in lwIP 1.4.1 and earlier, does not use random values for ID fields and source ports of DNS query packets, which makes it easier for man-in-the-middle attackers to conduct cache-poisoning attacks via spoofed reply packets.

    Published: 28 Nov 2014
    5
    Medium

    CVE-2014-6075

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

    Published: 28 Nov 2014
    5
    Medium

    CVE-2014-3407

    Last Modified: 12 Apr 2025

    The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(.2) and earlier does not properly allocate memory blocks during HTTP packet handling, which allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCuq68888.

    Published: 28 Nov 2014
    5.8
    Medium

    CVE-2014-4831

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to hijack sessions via unspecified vectors.

    Published: 28 Nov 2014
    4.3
    Medium

    CVE-2014-4832

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, allow remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.

    Published: 28 Nov 2014
    5
    Medium

    CVE-2015-1030

    Last Modified: 12 Apr 2025

    Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests that are rejected because the socket limit is reached.

    Published: 28 Nov 2014
    7.5
    High

    CVE-2015-1031

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap function in list.c or (2) "two additional unconfirmed use-after-free complaints made by Coverity scan." NOTE: some of these details are obtained from third party information.

    Published: 28 Nov 2014
    5
    Medium

    CVE-2014-5426

    Last Modified: 12 Apr 2025

    MatrikonOPC OPC Server for DNP3 1.2.3 and earlier allows remote attackers to cause a denial of service (unhandled exception and DNP3 process crash) via a crafted message.

    Published: 27 Nov 2014