CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2014-7959

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the tableprefix parameter.

    Published: 6 Nov 2014
    4.3
    Medium

    CVE-2014-7958

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/htaccess/bpsunlock.php in the BulletProof Security plugin before .51.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dbhost parameter.

    Published: 6 Nov 2014
    7.5
    High

    CVE-2014-8351

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in info.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz before 1.0.1 allows remote web servers to execute arbitrary SQL commands via the domain parameter.

    Published: 6 Nov 2014
    4.3
    Medium

    CVE-2014-8352

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in json.php in French National Commission on Informatics and Liberty (aka CNIL) CookieViz allows remote we servers to inject arbitrary web script or HTML via the max_date parameter.

    Published: 6 Nov 2014
    5
    Medium

    CVE-2014-8483

    Last Modified: 12 Apr 2025

    The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.

    Published: 6 Nov 2014
    4.3
    Medium

    CVE-2014-8508

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in s_network.asp in the Denon AVR-3313CI audio/video receiver allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to Friendlyname.

    Published: 6 Nov 2014
    4.3
    Medium

    CVE-2014-8653

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to inject arbitrary web script or HTML via the userData cookie.

    Published: 6 Nov 2014
    5
    Medium

    CVE-2014-8655

    Last Modified: 12 Apr 2025

    The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass authentication and obtain sensitive information via an (a) admin or a (b) root value in the userData cookie in a request to (1) CmgwWirelessSecurity.xml, (2) DocsisConfigFile.xml, or (3) CmgwBasicSetup.xml in xml/ or (4) basicDDNS.html, (5) basicLanUsers.html, or (6) rootDesc.xml.

    Published: 6 Nov 2014
    10
    Critical

    CVE-2014-8656

    Last Modified: 12 Apr 2025

    The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (1) admin for the admin account and (2) compalbn for the root account, which makes it easier for remote attackers to obtain access to certain sensitive information via unspecified vectors.

    Published: 6 Nov 2014
    5
    Medium

    CVE-2014-8659

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in SAP Environment, Health, and Safety allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 6 Nov 2014
    7.2
    High

    CVE-2014-8660

    Last Modified: 12 Apr 2025

    SAP Document Management Services allows local users to execute arbitrary commands via unspecified vectors.

    Published: 6 Nov 2014
    10
    Critical

    CVE-2014-8661

    Last Modified: 12 Apr 2025

    The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 6 Nov 2014
    7.8
    High

    CVE-2014-8662

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in SAP Payroll Process allows remote attackers to cause a denial of service via vectors related to session handling.

    Published: 6 Nov 2014
    7.5
    High

    CVE-2014-8663

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 6 Nov 2014
    7.5
    High

    CVE-2014-8664

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Product Safety (EHS-SAF) component in SAP Environment, Health, and Safety Management allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 6 Nov 2014
    5
    Medium

    CVE-2014-8665

    Last Modified: 12 Apr 2025

    The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files.

    Published: 6 Nov 2014
    7.8
    High

    CVE-2014-0023

    Last Modified: 21 Nov 2024

    OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

    Published: 6 Nov 2014
    6.5
    Medium

    CVE-2014-7813

    Last Modified: 20 Apr 2025

    Red Hat CloudForms 3 Management Engine (CFME) allows remote authenticated users to cause a denial of service (resource consumption) via vectors involving calls to the .to_sym rails function and lack of garbage collection of inserted symbols.

    Published: 6 Nov 2014
    5
    Medium

    CVE-2014-8709

    Last Modified: 12 Apr 2025

    The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.

    Published: 6 Nov 2014
    Unknown

    CVE-2014-2937

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3220. Reason: This candidate is a reservation duplicate of CVE-2014-3220. Notes: All CVE users should reference CVE-2014-3220 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Nov 2014
    3.5
    Low

    CVE-2014-8622

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the search-value parameter.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-2374

    Last Modified: 13 Oct 2025

    The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-2373

    Last Modified: 13 Oct 2025

    The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-5417

    Last Modified: 5 Nov 2025

    Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-5408

    Last Modified: 3 Nov 2025

    Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8546

    Last Modified: 12 Apr 2025

    Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Cinepak video data.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8547

    Last Modified: 12 Apr 2025

    libavcodec/gifdec.c in FFmpeg before 2.4.2 does not properly compute image heights, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted GIF data.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8548

    Last Modified: 12 Apr 2025

    Off-by-one error in libavcodec/smc.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Quicktime Graphics (aka SMC) video data.

    Published: 5 Nov 2014
    3.5
    Low

    CVE-2014-8326

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name, related to the libraries/DatabaseInterface.class.php code for SQL debug output and the js/server_status_monitor.js code for the server monitor page.

    Published: 5 Nov 2014
    4
    Medium

    CVE-2014-4769

    Last Modified: 12 Apr 2025

    IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 5 Nov 2014
    4.3
    Medium

    CVE-2014-4810

    Last Modified: 12 Apr 2025

    IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between the Cognos Mobile server and the Cognos Business Intelligence server after a logoff action on a mobile device, which makes it easier for remote attackers to bypass intended Business Intelligence restrictions by leveraging access to authentication data that was captured before this logoff.

    Published: 5 Nov 2014
    4.3
    Medium

    CVE-2014-4834

    Last Modified: 12 Apr 2025

    IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application crash) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8541

    Last Modified: 12 Apr 2025

    libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MJPEG data.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8542

    Last Modified: 12 Apr 2025

    libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8543

    Last Modified: 12 Apr 2025

    libavcodec/mmvideo.c in FFmpeg before 2.4.2 does not consider all lines of HHV Intra blocks during validation of image height, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted MM video data.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8544

    Last Modified: 12 Apr 2025

    libavcodec/tiff.c in FFmpeg before 2.4.2 does not properly validate bits-per-pixel fields, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted TIFF data.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8545

    Last Modified: 12 Apr 2025

    libavcodec/pngdec.c in FFmpeg before 2.4.2 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted PNG data.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8549

    Last Modified: 12 Apr 2025

    libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted On2 data.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-3693

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599.

    Published: 5 Nov 2014
    4.3
    Medium

    CVE-2014-3707

    Last Modified: 12 Apr 2025

    The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.

    Published: 5 Nov 2014
    7.5
    High

    CVE-2014-8626

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding.

    Published: 5 Nov 2014
    5
    Medium

    CVE-2014-7823

    Last Modified: 12 Apr 2025

    The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use of the VIR_DOMAIN_XML_SECURE flag.

    Published: 5 Nov 2014
    3.5
    Low

    CVE-2014-7828

    Last Modified: 12 Apr 2025

    FreeIPA 4.0.x before 4.0.5 and 4.1.x before 4.1.1, when 2FA is enabled, allows remote attackers to bypass the password requirement of the two-factor authentication leveraging an enabled OTP token, which triggers an anonymous bind.

    Published: 5 Nov 2014
    7.1
    High

    CVE-2014-2718

    Last Modified: 12 Apr 2025

    ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which allows man-in-the-middle (MITM) attackers to execute arbitrary code via a crafted image.

    Published: 4 Nov 2014
    4.3
    Medium

    CVE-2014-8471

    Last Modified: 12 Apr 2025

    CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to conduct replay attacks via unspecified vectors.

    Published: 4 Nov 2014
    6.8
    Medium

    CVE-2014-8472

    Last Modified: 12 Apr 2025

    CA Cloud Service Management (CSM) before Summer 2014 does not properly verify authentication tokens from an Identity Provider, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 4 Nov 2014
    6.8
    Medium

    CVE-2014-8473

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 4 Nov 2014
    7.5
    High

    CVE-2014-8474

    Last Modified: 12 Apr 2025

    CA Cloud Service Management (CSM) before Summer 2014 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 4 Nov 2014
    5
    Medium

    CVE-2014-6130

    Last Modified: 12 Apr 2025

    The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS.

    Published: 4 Nov 2014
    9
    Critical

    CVE-2014-7875

    Last Modified: 12 Apr 2025

    Unspecified vulnerability on the HP LaserJet CM3530 Multifunction Printer CC519A and CC520A with firmware before 53.236.2 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

    Published: 4 Nov 2014