CVE Feed

    Dashboard / CVE

    9
    Critical

    CVE-2014-6625

    Last Modified: 12 Apr 2025

    The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 19 Nov 2014
    10
    Critical

    CVE-2014-6626

    Last Modified: 12 Apr 2025

    Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown vectors.

    Published: 19 Nov 2014
    5
    Medium

    CVE-2014-6622

    Last Modified: 12 Apr 2025

    Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors.

    Published: 19 Nov 2014
    9
    Critical

    CVE-2014-6627

    Last Modified: 12 Apr 2025

    Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-5342.

    Published: 19 Nov 2014
    10
    Critical

    CVE-2014-5342

    Last Modified: 12 Apr 2025

    Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-6627.

    Published: 19 Nov 2014
    4.3
    Medium

    CVE-2014-8629

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Page visualization agents in Pandora FMS 5.1 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via the refr parameter to index.php.

    Published: 19 Nov 2014
    4.3
    Medium

    CVE-2014-7290

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Atlas Systems Aeon 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the (1) Action or (2) Form parameter to aeon.dll.

    Published: 19 Nov 2014
    7.5
    High

    CVE-2014-7903

    Last Modified: 12 Apr 2025

    Buffer overflow in OpenJPEG before r2911 in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG image.

    Published: 19 Nov 2014
    7.5
    High

    CVE-2014-7902

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.

    Published: 19 Nov 2014
    7.5
    High

    CVE-2014-7900

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.

    Published: 19 Nov 2014
    7.5
    High

    CVE-2014-7901

    Last Modified: 12 Apr 2025

    Integer overflow in the opj_t2_read_packet_data function in fxcodec/fx_libopenjpeg/libopenjpeg20/t2.c in OpenJPEG in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long segment in a JPEG image.

    Published: 19 Nov 2014
    6.5
    Medium

    CVE-2013-7449

    Last Modified: 12 Apr 2025

    The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 19 Nov 2014
    4
    Medium

    CVE-2014-7821

    Last Modified: 12 Apr 2025

    OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.

    Published: 19 Nov 2014
    4.3
    Medium

    CVE-2014-7850

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web UI in FreeIPA 4.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to breadcrumb navigation.

    Published: 19 Nov 2014
    7.5
    High

    CVE-2014-9093

    Last Modified: 12 Apr 2025

    LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.

    Published: 19 Nov 2014
    5.5
    Medium

    CVE-2014-9645

    Last Modified: 20 Apr 2025

    The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules via a / (slash) character in a module name, as demonstrated by an "ifconfig /usbserial up" command or a "mount -t /snd_pcm none /" command.

    Published: 19 Nov 2014
    8.8
    High

    CVE-2014-6324

    Last Modified: 22 Apr 2026

    The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature in a ticket, as exploited in the wild in November 2014, aka "Kerberos Checksum Vulnerability."

    Published: 18 Nov 2014
    6.8
    Medium

    CVE-2014-7996

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco Unified Computing System allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuq45477.

    Published: 18 Nov 2014
    2.1
    Low

    CVE-2014-4817

    Last Modified: 12 Apr 2025

    The server in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.3.5.10 and 7.x before 7.1.1.100 allows remote attackers to bypass intended access restrictions and replace file backups by using a certain backup option in conjunction with a filename that matches a previously used filename.

    Published: 18 Nov 2014
    4.3
    Medium

    CVE-2014-8475

    Last Modified: 12 Apr 2025

    FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before authentication is completed.

    Published: 18 Nov 2014
    7.5
    High

    CVE-2014-7146

    Last Modified: 12 Apr 2025

    The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a crafted (1) description field or (2) issuelink attribute in an XML file, which is not properly handled when executing the preg_replace function with the e modifier.

    Published: 18 Nov 2014
    6.4
    Medium

    CVE-2014-8598

    Last Modified: 12 Apr 2025

    The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arbitrary XML files via the import page or (2) obtain sensitive information via the export page. NOTE: this issue can be combined with CVE-2014-7146 to execute arbitrary PHP code.

    Published: 18 Nov 2014
    7.5
    High

    CVE-2014-4457

    Last Modified: 12 Apr 2025

    The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intended binary-execution restrictions via a crafted application that is run during a time period when debugging is not enabled.

    Published: 18 Nov 2014
    2.1
    Low

    CVE-2014-4455

    Last Modified: 12 Apr 2025

    dyld in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly handle overlapping segments in Mach-O executable files, which allows local users to bypass intended code-signing restrictions via a crafted file.

    Published: 18 Nov 2014
    7.2
    High

    CVE-2014-4451

    Last Modified: 12 Apr 2025

    Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lock-screen protection mechanism via a series of guesses.

    Published: 18 Nov 2014
    5.4
    Medium

    CVE-2014-4452

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4462.

    Published: 18 Nov 2014
    5
    Medium

    CVE-2014-4453

    Last Modified: 12 Apr 2025

    Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive information via unspecified vectors.

    Published: 18 Nov 2014
    5
    Medium

    CVE-2014-4458

    Last Modified: 12 Apr 2025

    The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vectors.

    Published: 18 Nov 2014
    6.8
    Medium

    CVE-2014-4459

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.

    Published: 18 Nov 2014
    2.1
    Low

    CVE-2014-4460

    Last Modified: 12 Apr 2025

    CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading cache files.

    Published: 18 Nov 2014
    9.3
    Critical

    CVE-2014-4461

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.

    Published: 18 Nov 2014
    5.8
    Medium

    CVE-2014-4462

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8.1.1 and Apple TV before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-4452.

    Published: 18 Nov 2014
    2.1
    Low

    CVE-2014-4463

    Last Modified: 12 Apr 2025

    Apple iOS before 8.1.1 allows physically proximate attackers to bypass the lock-screen protection mechanism, and view or transmit a Photo Library photo, via the FaceTime "Leave a Message" feature.

    Published: 18 Nov 2014
    4.3
    Medium

    CVE-2014-6096

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 18 Nov 2014
    5
    Medium

    CVE-2014-6095

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 18 Nov 2014
    5
    Medium

    CVE-2014-6098

    Last Modified: 12 Apr 2025

    IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request.

    Published: 18 Nov 2014
    4.3
    Medium

    CVE-2014-6107

    Last Modified: 12 Apr 2025

    IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to obtain sensitive cookie information by sniffing the network during an HTTP session.

    Published: 18 Nov 2014
    4.3
    Medium

    CVE-2014-6105

    Last Modified: 12 Apr 2025

    IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 18 Nov 2014
    2.1
    Low

    CVE-2014-6110

    Last Modified: 12 Apr 2025

    IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation.

    Published: 18 Nov 2014
    5
    Medium

    CVE-2014-7992

    Last Modified: 12 Apr 2025

    The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.

    Published: 18 Nov 2014
    5
    Medium

    CVE-2014-7899

    Last Modified: 12 Apr 2025

    Google Chrome before 38.0.2125.101 allows remote attackers to spoof the address bar by placing a blob: substring at the beginning of the URL, followed by the original URI scheme and a long username string.

    Published: 18 Nov 2014
    7.5
    High

    CVE-2014-7907

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in modules/screen_orientation/ScreenOrientationController.cpp in Blink, as used in Google Chrome before 39.0.2171.65, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger improper handling of a detached frame, related to the (1) lock and (2) unlock methods.

    Published: 18 Nov 2014
    7.5
    High

    CVE-2014-8962

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file.

    Published: 18 Nov 2014
    7.5
    High

    CVE-2014-7904

    Last Modified: 12 Apr 2025

    Buffer overflow in Skia, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 18 Nov 2014
    5
    Medium

    CVE-2014-7905

    Last Modified: 12 Apr 2025

    Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.

    Published: 18 Nov 2014
    7.5
    High

    CVE-2014-7906

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the Pepper plugins in Google Chrome before 39.0.2171.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Flash content that triggers an attempted PepperMediaDeviceManager access outside of the object's lifetime.

    Published: 18 Nov 2014
    5
    Medium

    CVE-2014-7909

    Last Modified: 12 Apr 2025

    effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which might allow remote attackers to cause a denial of service by rendering crafted data.

    Published: 18 Nov 2014
    6.5
    Medium

    CVE-2014-3599

    Last Modified: 21 Nov 2024

    HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy

    Published: 18 Nov 2014
    5.4
    Medium

    CVE-2014-8594

    Last Modified: 12 Apr 2025

    The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by leveraging hardware emulation services for HVM guests using Hardware Assisted Paging (HAP).

    Published: 18 Nov 2014
    1.9
    Low

    CVE-2014-8595

    Last Modified: 12 Apr 2025

    arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJMP, or (6) LRET far branch instruction.

    Published: 18 Nov 2014