CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2014-8866

    Last Modified: 12 Apr 2025

    The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving altering the high halves of registers while in 64-bit mode.

    Published: 27 Nov 2014
    4.9
    Medium

    CVE-2014-8867

    Last Modified: 12 Apr 2025

    The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) via unspecified vectors.

    Published: 27 Nov 2014
    6.8
    Medium

    CVE-2014-9099

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via a request to the whydowork_adsense page in wp-admin/options-general.php.

    Published: 26 Nov 2014
    6.8
    Medium

    CVE-2014-9101

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks or possibly have other unspecified impact via the (1) label parameter to admin/users/roles/, (2) lang[1][base][questions_account_type_5615100a931845eca8da20cfdf7327e0] in an AddAccountType action or (3) qst_name parameter in an addQuestion action to admin/questions/ajax-responder/, or (4) form_name or (5) restrictedUsername parameter to admin/restricted-usernames.

    Published: 26 Nov 2014
    5
    Medium

    CVE-2014-2037

    Last Modified: 12 Apr 2025

    Openswan 2.6.40 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. NOTE: this vulnerability exists because of an incomplete fix for CVE 2013-6466.

    Published: 26 Nov 2014
    3.5
    Low

    CVE-2014-9098

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the videoadssearchQuery parameter to (1) videoads/videoads.php, (2) video/video.php, or (3) playlist/playlist.php.

    Published: 26 Nov 2014
    4.3
    Medium

    CVE-2014-9100

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the idcode parameter in the whydowork_adsense page to wp-admin/options-general.php.

    Published: 26 Nov 2014
    4
    Medium

    CVE-2014-6609

    Last Modified: 12 Apr 2025

    The res_pjsip_pubsub module in Asterisk Open Source 12.x before 12.5.1 allows remote authenticated users to cause a denial of service (crash) via crafted headers in a SIP SUBSCRIBE request for an event package.

    Published: 26 Nov 2014
    4
    Medium

    CVE-2014-6610

    Last Modified: 12 Apr 2025

    Asterisk Open Source 11.x before 11.12.1 and 12.x before 12.5.1 and Certified Asterisk 11.6 before 11.6-cert6, when using the res_fax_spandsp module, allows remote authenticated users to cause a denial of service (crash) via an out of call message, which is not properly handled in the ReceiveFax dialplan application.

    Published: 26 Nov 2014
    7.2
    High

    CVE-2014-8419

    Last Modified: 12 Apr 2025

    Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to gain privileges via a Trojan horse file.

    Published: 26 Nov 2014
    4.3
    Medium

    CVE-2014-9094

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand parameter.

    Published: 26 Nov 2014
    7.5
    High

    CVE-2014-9095

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter to license/records.

    Published: 26 Nov 2014
    7.5
    High

    CVE-2014-9096

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) n parameter.

    Published: 26 Nov 2014
    7.5
    High

    CVE-2014-9097

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07-23, for WordPress allow (1) remote attackers to execute arbitrary SQL commands via the vid parameter in a myextract action to wp-admin/admin-ajax.php or (2) remote authenticated users to execute arbitrary SQL commands via the playlistId parameter in the newplaylist page or (3) videoId parameter in a newvideo page to wp-admin/admin.php.

    Published: 26 Nov 2014
    6.5
    Medium

    CVE-2014-9102

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote authenticated users to execute arbitrary SQL commands via the index value in an array parameter, as demonstrated by the topics[] parameter in an unfavorite action to index.php.

    Published: 26 Nov 2014
    4.3
    Medium

    CVE-2014-9103

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) index value of an array parameter or the filename parameter in the Content-Disposition header to the (2) file or (3) profile image upload functionality.

    Published: 26 Nov 2014
    6.8
    Medium

    CVE-2014-9104

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the XML-RPC API in the Desktop Client in OpenVPN Access Server 1.5.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) disconnecting established VPN sessions, (2) connect to arbitrary VPN servers, or (3) create VPN profiles and execute arbitrary commands via crafted API requests.

    Published: 26 Nov 2014
    10
    Critical

    CVE-2014-8551

    Last Modified: 12 Apr 2025

    The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.

    Published: 26 Nov 2014
    5
    Medium

    CVE-2014-8552

    Last Modified: 12 Apr 2025

    The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to read arbitrary files via crafted packets.

    Published: 26 Nov 2014
    3.5
    Low

    CVE-2014-6093

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 26 Nov 2014
    5
    Medium

    CVE-2014-8005

    Last Modified: 12 Apr 2025

    Race condition in the lighttpd module in Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (process reload) by establishing many TCP sessions, aka Bug ID CSCuq45239.

    Published: 26 Nov 2014
    4.3
    Medium

    CVE-2014-6196

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal configuration, leading to improper construction of a response page by an application.

    Published: 26 Nov 2014
    10
    Critical

    CVE-2014-7247

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro Pro 2; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen; and Ichitaro 2014 Tetsu allows remote attackers to execute arbitrary code via a crafted file.

    Published: 26 Nov 2014
    7.8
    High

    CVE-2014-9114

    Last Modified: 4 Dec 2025

    Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.

    Published: 26 Nov 2014
    5
    Medium

    CVE-2014-9130

    Last Modified: 12 Apr 2025

    scanner.c in LibYAML 0.1.5 and 0.1.6, as used in the YAML-LibYAML (aka YAML-XS) module for Perl, allows context-dependent attackers to cause a denial of service (assertion failure and crash) via vectors involving line-wrapping.

    Published: 26 Nov 2014
    5
    Medium

    CVE-2014-9116

    Last Modified: 12 Apr 2025

    The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.

    Published: 26 Nov 2014
    4.3
    Medium

    CVE-2014-9031

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field, as demonstrated by a comment or a post.

    Published: 25 Nov 2014
    4.3
    Medium

    CVE-2014-9032

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Nov 2014
    4.3
    Medium

    CVE-2014-9039

    Last Modified: 12 Apr 2025

    wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

    Published: 25 Nov 2014
    6.8
    Medium

    CVE-2014-9033

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in wp-login.php in WordPress 3.7.4, 3.8.4, 3.9.2, and 4.0 allows remote attackers to hijack the authentication of arbitrary users for requests that reset passwords.

    Published: 25 Nov 2014
    5
    Medium

    CVE-2014-9034

    Last Modified: 12 Apr 2025

    wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.

    Published: 25 Nov 2014
    4.3
    Medium

    CVE-2014-9035

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Nov 2014
    4.3
    Medium

    CVE-2014-9036

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a post.

    Published: 25 Nov 2014
    6.8
    Medium

    CVE-2014-9037

    Last Modified: 12 Apr 2025

    WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

    Published: 25 Nov 2014
    6.4
    Medium

    CVE-2014-9038

    Last Modified: 12 Apr 2025

    wp-includes/http.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to conduct server-side request forgery (SSRF) attacks by referring to a 127.0.0.0/8 resource.

    Published: 25 Nov 2014
    5
    Medium

    CVE-2014-8004

    Last Modified: 12 Apr 2025

    Cisco IOS XR allows remote attackers to cause a denial of service (LISP process reload) by establishing many LISP TCP sessions, aka Bug ID CSCuq90378.

    Published: 25 Nov 2014
    7.5
    High

    CVE-2014-8001

    Last Modified: 12 Apr 2025

    Buffer overflow in decode.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

    Published: 25 Nov 2014
    7.5
    High

    CVE-2014-8002

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in decode_slice.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

    Published: 25 Nov 2014
    6.5
    Medium

    CVE-2014-8558

    Last Modified: 12 Apr 2025

    JExperts Channel Platform 5.0.33_CCB allows remote authenticated users to bypass access restrictions via crafted action and key parameters.

    Published: 25 Nov 2014
    7.2
    High

    CVE-2014-1421

    Last Modified: 12 Apr 2025

    mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

    Published: 25 Nov 2014
    7.5
    High

    CVE-2014-8367

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) 6.2.x, 6.3.x before 6.3.6, and 6.4.x before 6.4.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 25 Nov 2014
    9
    Critical

    CVE-2014-8368

    Last Modified: 12 Apr 2025

    The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbitrary commands via unspecified vectors.

    Published: 25 Nov 2014
    9
    Critical

    CVE-2014-8420

    Last Modified: 12 Apr 2025

    The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 25 Nov 2014
    7.8
    High

    CVE-2014-8678

    Last Modified: 12 Apr 2025

    The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related to "saveFile."

    Published: 25 Nov 2014
    8.8
    High

    CVE-2014-8439

    Last Modified: 21 Apr 2026

    Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.

    Published: 25 Nov 2014
    7.5
    High

    CVE-2014-9157

    Last Modified: 12 Apr 2025

    Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.

    Published: 25 Nov 2014
    7.5
    High

    CVE-2014-9028

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file.

    Published: 25 Nov 2014
    7.5
    High

    CVE-2014-9087

    Last Modified: 12 Apr 2025

    Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.

    Published: 25 Nov 2014
    3.5
    Low

    CVE-2014-8349

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Liferay Portal Enterprise Edition (EE) 6.2 SP8 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the _20_body parameter in the comment field in an uploaded file.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-8413

    Last Modified: 12 Apr 2025

    The res_pjsip_acl module in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 does not properly create and load ACLs defined in pjsip.conf at startup, which allows remote attackers to bypass intended PJSIP ACL rules.

    Published: 24 Nov 2014