CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-8414

    Last Modified: 12 Apr 2025

    ConfBridge in Asterisk 11.x before 11.14.1 and Certified Asterisk 11.6 before 11.6-cert8 does not properly handle state changes, which allows remote attackers to cause a denial of service (channel hang and memory consumption) by causing transitions to be delayed, which triggers a state change from hung up to waiting for media.

    Published: 24 Nov 2014
    6.4
    Medium

    CVE-2014-1424

    Last Modified: 12 Apr 2025

    apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."

    Published: 24 Nov 2014
    3.5
    Low

    CVE-2014-8986

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the selection list in the filters in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via a crafted config option, a different vulnerability than CVE-2014-8987.

    Published: 24 Nov 2014
    6.8
    Medium

    CVE-2014-9015

    Last Modified: 12 Apr 2025

    Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-9016

    Last Modified: 12 Apr 2025

    The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-8412

    Last Modified: 12 Apr 2025

    The (1) VoIP channel drivers, (2) DUNDi, and (3) Asterisk Manager Interface (AMI) in Asterisk Open Source 1.8.x before 1.8.32.1, 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8.28 before 1.8.28-cert3 and 11.6 before 11.6-cert8 allows remote attackers to bypass the ACL restrictions via a packet with a source IP that does not share the address family as the first ACL entry.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-8415

    Last Modified: 12 Apr 2025

    Race condition in the chan_pjsip channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a cancel request for a SIP session with a queued action to (1) answer a session or (2) send ringing.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-8416

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the PJSIP channel driver in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1, when using the res_pjsip_refer module, allows remote attackers to cause a denial of service (crash) via an in-dialog INVITE with Replaces message, which triggers the channel to be hung up.

    Published: 24 Nov 2014
    6.5
    Medium

    CVE-2014-8417

    Last Modified: 12 Apr 2025

    ConfBridge in Asterisk 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 11.6 before 11.6-cert8 allows remote authenticated users to (1) gain privileges via vectors related to an external protocol to the CONFBRIDGE dialplan function or (2) execute arbitrary system commands via a crafted ConfbridgeStartRecord AMI action.

    Published: 24 Nov 2014
    9
    Critical

    CVE-2014-8418

    Last Modified: 12 Apr 2025

    The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8 before 1.8.28-cert8 and 11.6 before 11.6-cert8 allows remote authenticated users to gain privileges via a call from an external protocol, as demonstrated by the AMI protocol.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-8627

    Last Modified: 12 Apr 2025

    PolarSSL 1.3.8 does not properly negotiate the signature algorithm to use, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

    Published: 24 Nov 2014
    4
    Medium

    CVE-2014-8988

    Last Modified: 12 Apr 2025

    MantisBT before 1.2.18 allows remote authenticated users to bypass the $g_download_attachments_threshold and $g_view_attachments_threshold restrictions and read attachments for private projects by leveraging access to a project that does not restrict access to attachments and a request to the download URL.

    Published: 24 Nov 2014
    2.1
    Low

    CVE-2014-7835

    Last Modified: 12 Apr 2025

    webservice/upload.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not ensure that a file upload is for a private or draft area, which allows remote authenticated users to upload files containing JavaScript, and consequently conduct cross-site scripting (XSS) attacks, by specifying the profile-picture area.

    Published: 24 Nov 2014
    5.5
    Medium

    CVE-2014-7837

    Last Modified: 12 Apr 2025

    mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remove wiki pages by leveraging delete access within a different subwiki.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-7845

    Last Modified: 12 Apr 2025

    The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary passwords, which allows remote attackers to obtain access via a brute-force attack.

    Published: 24 Nov 2014
    6.8
    Medium

    CVE-2014-7836

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for a (1) mod/lti/request_tool.php or (2) mod/lti/instructor_edit_tool_type.php request.

    Published: 24 Nov 2014
    4.3
    Medium

    CVE-2014-9059

    Last Modified: 12 Apr 2025

    lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 characters during interaction with AJAX scripts.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-9060

    Last Modified: 12 Apr 2025

    The LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not properly restrict the parameters used in a return URL, which allows remote attackers to trigger the generation of arbitrary messages via a modified URL, related to mod/lti/locallib.php and mod/lti/return.php.

    Published: 24 Nov 2014
    4
    Medium

    CVE-2014-7834

    Last Modified: 12 Apr 2025

    mod/forum/externallib.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 does not verify group permissions, which allows remote authenticated users to access a forum via the forum_get_discussions web service.

    Published: 24 Nov 2014
    4
    Medium

    CVE-2014-7833

    Last Modified: 12 Apr 2025

    mod/data/edit.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 sets a certain group ID to zero upon a database-entry change, which allows remote authenticated users to obtain sensitive information by accessing the database after an edit by a teacher.

    Published: 24 Nov 2014
    3.5
    Low

    CVE-2014-7830

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in mod/feedback/mapcourse.php in the Feedback module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to inject arbitrary web script or HTML by leveraging the mod/feedback:mapcourse capability to provide a searchcourse parameter.

    Published: 24 Nov 2014
    4
    Medium

    CVE-2014-7831

    Last Modified: 12 Apr 2025

    lib/classes/grades_external.php in Moodle 2.7.x before 2.7.3 does not consider the moodle/grade:viewhidden capability before displaying hidden grades, which allows remote authenticated users to obtain sensitive information by leveraging the student role to access the get_grades web service.

    Published: 24 Nov 2014
    4
    Medium

    CVE-2014-7832

    Last Modified: 12 Apr 2025

    mod/lti/launch.php in the LTI module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 performs access control at the course level rather than at the activity level, which allows remote authenticated users to bypass the mod/lti:view capability requirement by viewing an activity instance.

    Published: 24 Nov 2014
    6.8
    Medium

    CVE-2014-7838

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Forum module in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allow remote attackers to hijack the authentication of arbitrary users for requests that set a tracking preference within (1) mod/forum/deprecatedlib.php, (2) mod/forum/forum.js, (3) mod/forum/index.php, or (4) mod/forum/lib.php.

    Published: 24 Nov 2014
    4
    Medium

    CVE-2014-7846

    Last Modified: 12 Apr 2025

    tag/tag_autocomplete.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not consider the moodle/tag:edit capability before adding a tag, which allows remote authenticated users to bypass intended access restrictions via an AJAX request.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-7847

    Last Modified: 12 Apr 2025

    iplookup/index.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote attackers to cause a denial of service (resource consumption) by triggering the calculation of an estimated latitude and longitude for an IP address.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-7848

    Last Modified: 12 Apr 2025

    lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

    Published: 24 Nov 2014
    9
    Critical

    CVE-2014-5314

    Last Modified: 12 Apr 2025

    Buffer overflow in Cybozu Office 9 and 10 before 10.1.0, Mailwise 4 and 5 before 5.1.4, and Dezie 8 before 8.1.1 allows remote authenticated users to execute arbitrary code via e-mail messages.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9668

    Last Modified: 12 Apr 2025

    The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Web Open Font Format (WOFF) file.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9657

    Last Modified: 12 Apr 2025

    The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9658

    Last Modified: 12 Apr 2025

    The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9659

    Last Modified: 12 Apr 2025

    cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted OpenType font. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2240.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9663

    Last Modified: 12 Apr 2025

    The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted cmap SFNT table.

    Published: 24 Nov 2014
    6.8
    Medium

    CVE-2014-9664

    Last Modified: 12 Apr 2025

    FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.

    Published: 24 Nov 2014
    6.8
    Medium

    CVE-2014-9666

    Last Modified: 12 Apr 2025

    The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted embedded bitmap.

    Published: 24 Nov 2014
    6.8
    Medium

    CVE-2014-9667

    Last Modified: 12 Apr 2025

    sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.

    Published: 24 Nov 2014
    6.8
    Medium

    CVE-2014-9669

    Last Modified: 12 Apr 2025

    Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.

    Published: 24 Nov 2014
    4.3
    Medium

    CVE-2014-9670

    Last Modified: 12 Apr 2025

    Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.

    Published: 24 Nov 2014
    4.3
    Medium

    CVE-2014-9671

    Last Modified: 12 Apr 2025

    Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly incremented.

    Published: 24 Nov 2014
    6.8
    Medium

    CVE-2014-9673

    Last Modified: 12 Apr 2025

    Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-6407

    Last Modified: 12 Apr 2025

    Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-6408

    Last Modified: 12 Apr 2025

    Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.

    Published: 24 Nov 2014
    5
    Medium

    CVE-2014-9140

    Last Modified: 12 Apr 2025

    Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9656

    Last Modified: 12 Apr 2025

    The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted OpenType font.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9660

    Last Modified: 12 Apr 2025

    The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9661

    Last Modified: 12 Apr 2025

    type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted Type42 font.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9662

    Last Modified: 12 Apr 2025

    cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted OTF font.

    Published: 24 Nov 2014
    7.5
    High

    CVE-2014-9665

    Last Modified: 12 Apr 2025

    The Load_SBit_Png function in sfnt/pngshim.c in FreeType before 2.5.4 does not restrict the rows and pitch values of PNG data, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact by embedding a PNG file in a .ttf font file.

    Published: 24 Nov 2014
    5.8
    Medium

    CVE-2014-9672

    Last Modified: 12 Apr 2025

    Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from process memory via a crafted FOND resource in a Mac font file.

    Published: 24 Nov 2014
    6.1
    Medium

    CVE-2016-5699

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.

    Published: 24 Nov 2014