CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-8964

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.

    Published: 18 Nov 2014
    6.4
    Medium

    CVE-2014-7839

    Last Modified: 12 Apr 2025

    DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

    Published: 18 Nov 2014
    7.5
    High

    CVE-2014-7908

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a large atom in (1) MPEG-4 or (2) QuickTime .mov data.

    Published: 18 Nov 2014
    7.5
    High

    CVE-2014-7910

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 18 Nov 2014
    7.8
    High

    CVE-2014-9428

    Last Modified: 12 Apr 2025

    The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of an amount of memory, which allows remote attackers to cause a denial of service (mesh-node system crash) via fragmented packets.

    Published: 18 Nov 2014
    4.3
    Medium

    CVE-2012-1669

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in index.php in phpMoneyBooks before 1.0.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Published: 17 Nov 2014
    4.3
    Medium

    CVE-2012-6665

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in index.php in phpMoneyBooks 1.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2012-1669. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this issue might have been fixed in 1.0.3.

    Published: 17 Nov 2014
    9
    Critical

    CVE-2013-3678

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in SAP Governance, Risk, and Compliance (GRC) allow remote authenticated users to gain privileges and execute arbitrary programs via a crafted (1) RFC or (2) SOAP-RFC request.

    Published: 17 Nov 2014
    4.3
    Medium

    CVE-2014-8954

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpSound 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) Title or (2) Description fields in a playlist or the (3) filter parameter in an explore action to index.php.

    Published: 17 Nov 2014
    4.3
    Medium

    CVE-2014-8955

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the cscf[name] parameter to contact-us/.

    Published: 17 Nov 2014
    6.5
    Medium

    CVE-2014-8498

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.

    Published: 17 Nov 2014
    6.5
    Medium

    CVE-2014-8499

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allow remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter to (1) SQLAdvancedALSearchResult.cc or (2) AdvancedSearchResult.cc.

    Published: 17 Nov 2014
    7.5
    High

    CVE-2014-8517

    Last Modified: 12 Apr 2025

    The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an HTTP redirect.

    Published: 17 Nov 2014
    7.5
    High

    CVE-2014-8596

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php.

    Published: 17 Nov 2014
    4.3
    Medium

    CVE-2014-8732

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in phpMemcachedAdmin 1.2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Nov 2014
    6.2
    Medium

    CVE-2014-8727

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in F5 BIG-IP before 10.2.2 allow local users with the "Resource Administrator" or "Administrator" role to enumerate and delete arbitrary files via a .. (dot dot) in the name parameter to (1) tmui/Control/jspmap/tmui/system/archive/properties.jsp or (2) tmui/Control/form.

    Published: 17 Nov 2014
    6.8
    Medium

    CVE-2014-8953

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Php Scriptlerim Who's Who script allow remote attackers to hijack the authentication of administrators or requests that (1) add an admin account via a request to filepath/yonetim/plugin/adminsave.php or have unspecified impact via a request to (2) ayarsave.php, (3) uyesave.php, (4) slaytadd.php, or (5) slaytsave.php.

    Published: 17 Nov 2014
    5
    Medium

    CVE-2014-7829

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.

    Published: 17 Nov 2014
    3.5
    Low

    CVE-2014-0228

    Last Modified: 12 Apr 2025

    Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.

    Published: 16 Nov 2014
    7.1
    High

    CVE-2014-8951

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Check Point Security Gateway R75, R76, R77, and R77.10, when UserCheck is enabled and the (1) Application Control, (2) URL Filtering, (3) DLP, (4) Threat Emulation, (5) Anti-Bot, or (6) Anti-Virus blade is used, allows remote attackers to cause a denial of service (fwk0 process crash, core dump, and restart) via a redirect to the UserCheck page.

    Published: 16 Nov 2014
    7.1
    High

    CVE-2014-8952

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Check Point Security Gateway R75.40VS, R75.45, R75.46, R75.47, R76, R77, and R77.10, when the (1) IPS blade, (2) IPsec Remote Access, (3) Mobile Access / SSL VPN blade, (4) SSL Network Extender, (5) Identify Awareness blade, (6) HTTPS Inspection, (7) UserCheck, or (8) Data Leak Prevention blade module is enabled, allow remote attackers to cause a denial of service ("stability issue") via an unspecified "traffic condition."

    Published: 16 Nov 2014
    7.1
    High

    CVE-2014-8950

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Check Point Security Gateway R77 and R77.10, when the (1) URL Filtering or (2) Identity Awareness blade is used, allows remote attackers to cause a denial of service (crash) via vectors involving an HTTPS request.

    Published: 16 Nov 2014
    6.8
    Medium

    CVE-2014-8948

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote attackers to hijack the authentication of administrators for requests that with an unspecified impact via the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to execute arbitrary commands.

    Published: 16 Nov 2014
    7.2
    High

    CVE-2013-0347

    Last Modified: 12 Apr 2025

    The Gentoo init script for webfs uses world-readable permissions for /var/log/webfsd.log, which allows local users to have unspecified impact by reading the file.

    Published: 16 Nov 2014
    5
    Medium

    CVE-2014-3755

    Last Modified: 12 Apr 2025

    The QSvg module in Qt, as used in the Mumble client 1.2.x before 1.2.6, allows remote attackers to cause a denial of service (hang and resource consumption) via a local file reference in an (1) image tag or (2) XML stylesheet in an SVG file.

    Published: 16 Nov 2014
    5
    Medium

    CVE-2014-3756

    Last Modified: 12 Apr 2025

    The client in Mumble 1.2.x before 1.2.6 allows remote attackers to force the loading of an external file and cause a denial of service (hang and resource consumption) via a crafted string that is treated as rich-text by a Qt widget, as demonstrated by the (1) user or (2) channel name in a Qt dialog, (3) subject common name or (4) email address to the Certificate Wizard, or (5) server name in a tooltip.

    Published: 16 Nov 2014
    6
    Medium

    CVE-2014-8949

    Last Modified: 12 Apr 2025

    The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to allow remote attackers to execute code. NOTE: it is not clear whether this issue itself crosses privileges.

    Published: 16 Nov 2014
    5
    Medium

    CVE-2013-3737

    Last Modified: 12 Apr 2025

    The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (Apache::Session::File) and certain authentication extensions, allows remote attackers to reuse unauthorized sessions and obtain user preferences and caches via unspecified vectors.

    Published: 16 Nov 2014
    6
    Medium

    CVE-2012-2301

    Last Modified: 12 Apr 2025

    The Ubercart module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer product classes" permission to execute arbitrary PHP code via unspecified vectors.

    Published: 16 Nov 2014
    5
    Medium

    CVE-2014-2268

    Last Modified: 12 Apr 2025

    views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-install the application via a request that sets the X-Requested-With HTTP header, as demonstrated by executing arbitrary PHP code via the db_name parameter.

    Published: 16 Nov 2014
    6.4
    Medium

    CVE-2014-2681

    Last Modified: 12 Apr 2025

    Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, and possibly cause a denial of service (CPU and memory consumption) via an XML External Entity (XXE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-5657.

    Published: 16 Nov 2014
    6.4
    Medium

    CVE-2014-2684

    Last Modified: 12 Apr 2025

    The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 does not verify that the openid_op_endpoint value identifies the same Identity Provider as the provider used in the association handle, which allows remote attackers to bypass authentication and spoof arbitrary OpenID identities by using a malicious OpenID Provider that generates OpenID tokens with arbitrary identifier and claimed_id values.

    Published: 16 Nov 2014
    6.8
    Medium

    CVE-2014-2682

    Last Modified: 12 Apr 2025

    Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0, when PHP-FPM is used, does not properly share the libxml_disable_entity_loader setting between threads, which might allow remote attackers to conduct XML External Entity (XXE) attacks via an XML external entity declaration in conjunction with an entity reference. NOTE: this issue exists because of an incomplete fix for CVE-2012-5657.

    Published: 16 Nov 2014
    5
    Medium

    CVE-2014-2683

    Last Modified: 12 Apr 2025

    Zend Framework 1 (ZF1) before 1.12.4, Zend Framework 2 before 2.1.6 and 2.2.x before 2.2.6, ZendOpenId, ZendRest, ZendService_AudioScrobbler, ZendService_Nirvanix, ZendService_SlideShare, ZendService_Technorati, and ZendService_WindowsAzure before 2.0.2, ZendService_Amazon before 2.0.3, and ZendService_Api before 1.0.0 allow remote attackers to cause a denial of service (CPU consumption) via (1) recursive or (2) circular references in an XML entity definition in an XML DOCTYPE declaration, aka an XML Entity Expansion (XEE) attack. NOTE: this issue exists because of an incomplete fix for CVE-2012-6532.

    Published: 16 Nov 2014
    6.4
    Medium

    CVE-2014-3500

    Last Modified: 12 Apr 2025

    Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.

    Published: 15 Nov 2014
    4.3
    Medium

    CVE-2014-3501

    Last Modified: 12 Apr 2025

    Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView.

    Published: 15 Nov 2014
    4.3
    Medium

    CVE-2014-3502

    Last Modified: 12 Apr 2025

    Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.

    Published: 15 Nov 2014
    Unknown

    CVE-2014-8565

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8518. Reason: This candidate is a duplicate of CVE-2014-8518. Notes: All CVE users should reference CVE-2014-8518 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Nov 2014
    6.1
    Medium

    CVE-2014-7997

    Last Modified: 12 Apr 2025

    The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-renewal attempts, which allows remote attackers to cause a denial of service (device restart) by triggering a transition into a recovery state that was intended to involve a network-interface restart but actually involves a full device restart, aka Bug ID CSCtn16281.

    Published: 15 Nov 2014
    7.1
    High

    CVE-2014-7998

    Last Modified: 12 Apr 2025

    Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a malformed EAP packet, aka Bug ID CSCul15509.

    Published: 15 Nov 2014
    4.3
    Medium

    CVE-2014-7248

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IPA iLogScanner 4.0 allows remote attackers to inject arbitrary web script or HTML by triggering a crafted entry in a log file.

    Published: 15 Nov 2014
    5.3
    Medium

    CVE-2014-9635

    Last Modified: 20 Apr 2025

    Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

    Published: 15 Nov 2014
    4.6
    Medium

    CVE-2014-8989

    Last Modified: 12 Apr 2025

    The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c.

    Published: 15 Nov 2014
    5.3
    Medium

    CVE-2014-9634

    Last Modified: 20 Apr 2025

    Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.

    Published: 15 Nov 2014
    5
    Medium

    CVE-2014-5325

    Last Modified: 12 Apr 2025

    The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 14 Nov 2014
    10
    Critical

    CVE-2014-7878

    Last Modified: 12 Apr 2025

    The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses the same security keys across different customers' installations, which allows remote attackers to execute arbitrary code by leveraging these keys for a connection.

    Published: 14 Nov 2014
    Unknown

    CVE-2014-8842

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 14 Nov 2014
    Unknown

    CVE-2014-8841

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 14 Nov 2014
    6.4
    Medium

    CVE-2014-3068

    Last Modified: 12 Apr 2025

    IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and before 5.0 SR16 FP7 (5.0.16.7) allows attackers to obtain the private key from a Certificate Management System (CMS) keystore via a brute force attack.

    Published: 14 Nov 2014
    4.3
    Medium

    CVE-2014-5326

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Nov 2014