CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2014-4974

    Last Modified: 12 Apr 2025

    The ESET Personal Firewall NDIS filter (EpFwNdis.sys) kernel mode driver, aka Personal Firewall module before Build 1212 (20140609), as used in multiple ESET products 5.0 through 7.0, allows local users to obtain sensitive information from kernel memory via crafted IOCTL calls.

    Published: 4 Nov 2014
    4.3
    Medium

    CVE-2014-8593

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Allomani Weblinks 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) default URI to admin.php or the (2) id parameter to admin.php or (3) go.php.

    Published: 4 Nov 2014
    5
    Medium

    CVE-2014-8585

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.

    Published: 4 Nov 2014
    6.8
    Medium

    CVE-2013-7057

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1.0/files/.

    Published: 4 Nov 2014
    6.5
    Medium

    CVE-2014-5387

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in EllisLab ExpressionEngine before 2.9.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) column_filter or (2) category[] parameter to system/index.php or the (3) tbl_sort[0][] parameter in the comment module to system/index.php.

    Published: 4 Nov 2014
    6.5
    Medium

    CVE-2014-7176

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman.

    Published: 4 Nov 2014
    7.5
    High

    CVE-2014-8339

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in midroll.php in Nuevolab Nuevoplayer for ClipShare 8.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ch parameter.

    Published: 4 Nov 2014
    4.3
    Medium

    CVE-2014-8584

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Dorado Spider Video Player (aka WordPress Video Player) plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Nov 2014
    7.5
    High

    CVE-2014-8586

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to execute arbitrary SQL commands via the calid parameter.

    Published: 4 Nov 2014
    7.5
    High

    CVE-2014-8587

    Last Modified: 12 Apr 2025

    SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures via unspecified vectors.

    Published: 4 Nov 2014
    7.5
    High

    CVE-2014-8588

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in metadata.xsjs in SAP HANA 1.00.60.379371 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 4 Nov 2014
    5
    Medium

    CVE-2014-8589

    Last Modified: 12 Apr 2025

    Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (resource consumption) via crafted requests.

    Published: 4 Nov 2014
    4.3
    Medium

    CVE-2014-8590

    Last Modified: 12 Apr 2025

    XML external entity (XXE) vulnerability in the Web Service Navigator in SAP NetWeaver Application Server (AS) Java allows remote attackers to access arbitrary files via a crafted request.

    Published: 4 Nov 2014
    5
    Medium

    CVE-2014-8591

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in SAP Internet Communication Manager (ICM), as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process termination) via unknown vectors.

    Published: 4 Nov 2014
    5
    Medium

    CVE-2014-8592

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in SAP Host Agent, as used in SAP NetWeaver 7.02 and 7.3, allows remote attackers to cause a denial of service (process termination) via a crafted request.

    Published: 4 Nov 2014
    5
    Medium

    CVE-2014-4311

    Last Modified: 12 Apr 2025

    Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by reading HTML source code of the database connection and email settings page.

    Published: 4 Nov 2014
    7.2
    High

    CVE-2014-8651

    Last Modified: 12 Apr 2025

    The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafted ntpUtility (ntp utility name) argument.

    Published: 4 Nov 2014
    5
    Medium

    CVE-2014-8710

    Last Modified: 12 Apr 2025

    The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

    Published: 4 Nov 2014
    3.6
    Low

    CVE-2014-8737

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.

    Published: 4 Nov 2014
    7.5
    High

    CVE-2014-0487

    Last Modified: 12 Apr 2025

    APT before 1.0.9 does not verify downloaded files if they have been modified as indicated using the If-Modified-Since header, which has unspecified impact and attack vectors.

    Published: 3 Nov 2014
    7.5
    High

    CVE-2014-0489

    Last Modified: 12 Apr 2025

    APT before 1.0.9, when the Acquire::GzipIndexes option is enabled, does not validate checksums, which allows remote attackers to execute arbitrary code via a crafted package.

    Published: 3 Nov 2014
    7.5
    High

    CVE-2014-0490

    Last Modified: 12 Apr 2025

    The apt-get download command in APT before 1.0.9 does not properly validate signatures for packages, which allows remote attackers to execute arbitrary code via a crafted package.

    Published: 3 Nov 2014
    6.8
    Medium

    CVE-2014-0488

    Last Modified: 12 Apr 2025

    APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.

    Published: 3 Nov 2014
    7.5
    High

    CVE-2014-7228

    Last Modified: 12 Apr 2025

    Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Professional for WordPress 1.0.b1 through 1.1.3; Solo 1.0.b1 through 1.1.2; Admin Tools Core and Professional 2.0.0 through 2.4.4; and CMS Update 1.0.a1 through 1.0.1, when performing a backup or update for an archive, does not delete parameters from $_GET and $_POST when it is cleansing $_REQUEST, but later accesses $_GET and $_POST using the getQueryParam function, which allows remote attackers to bypass encryption and execute arbitrary code via a command message that extracts a crafted archive.

    Published: 3 Nov 2014
    4.6
    Medium

    CVE-2014-8494

    Last Modified: 12 Apr 2025

    ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local users to gain privileges via a Trojan horse file.

    Published: 3 Nov 2014
    6.8
    Medium

    CVE-2014-5272

    Last Modified: 12 Apr 2025

    libavcodec/iff.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.2.x before 2.2.7, and 2.3.x before 2.3.2 allows remote attackers to have unspecified impact via a crafted iff image, which triggers an out-of-bounds array access, related to the rgb8 and rgbn formats.

    Published: 3 Nov 2014
    7.2
    High

    CVE-2014-5507

    Last Modified: 12 Apr 2025

    iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local users to gain privileges via a Trojan horse file.

    Published: 3 Nov 2014
    7.5
    High

    CVE-2014-5271

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the encode_slice function in libavcodec/proresenc_kostya.c in FFMpeg before 1.1.14, 1.2.x before 1.2.8, 2.x before 2.2.7, and 2.3.x before 2.3.3 and Libav before 10.5 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 3 Nov 2014
    7.5
    High

    CVE-2014-8350

    Last Modified: 12 Apr 2025

    Smarty before 3.1.21 allows remote attackers to bypass the secure mode restrictions and execute arbitrary PHP code as demonstrated by "{literal}<{/literal}script language=php>" in a template.

    Published: 3 Nov 2014
    7.5
    High

    CVE-2014-3674

    Last Modified: 12 Apr 2025

    Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of arbitrary gears via unspecified vectors.

    Published: 3 Nov 2014
    6.4
    Medium

    CVE-2014-8566

    Last Modified: 12 Apr 2025

    The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."

    Published: 3 Nov 2014
    4
    Medium

    CVE-2014-9913

    Last Modified: 20 Apr 2025

    Buffer overflow in the list_files function in list.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via vectors related to the compression method.

    Published: 3 Nov 2014
    9.4
    Critical

    CVE-2014-8567

    Last Modified: 12 Apr 2025

    The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.

    Published: 3 Nov 2014
    5
    Medium

    CVE-2014-8738

    Last Modified: 12 Apr 2025

    The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.

    Published: 2 Nov 2014
    5
    Medium

    CVE-2014-9636

    Last Modified: 12 Apr 2025

    unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.

    Published: 2 Nov 2014
    2.6
    Low

    CVE-2015-2625

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JSSE.

    Published: 2 Nov 2014
    5.5
    Medium

    CVE-2014-6032

    Last Modified: 12 Apr 2025

    Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Controller 11.0 through 11.6.0 and 10.0.0 through 10.2.4, AAM 11.4.0 through 11.6.0, ARM 11.3.0 through 11.6.0, Analytics 11.0.0 through 11.6.0, APM and Edge Gateway 11.0.0 through 11.6.0 and 10.1.0 through 10.2.4, PEM 11.3.0 through 11.6.0, PSM 11.0.0 through 11.4.1 and 10.0.0 through 10.2.4, and WOM 11.0.0 through 11.3.0 and 10.0.0 through 10.2.4 and Enterprise Manager 3.0.0 through 3.1.1 and 2.1.0 through 2.3.0 allow remote authenticated users to read arbitrary files and cause a denial of service via a crafted request, as demonstrated using (1) viewList or (2) deal elements.

    Published: 1 Nov 2014
    6.4
    Medium

    CVE-2014-8582

    Last Modified: 12 Apr 2025

    FortiNet FortiADC-E with firmware 3.1.1 before 4.0.5 and Coyote Point Equalizer with firmware 10.2.0a allows remote attackers to obtain access to arbitrary subnets via unspecified vectors.

    Published: 1 Nov 2014
    3.3
    Low

    CVE-2014-8243

    Last Modified: 12 Apr 2025

    Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain the administrator's MD5 password hash via a direct request for the /.htpasswd URI.

    Published: 1 Nov 2014
    7.5
    High

    CVE-2014-8244

    Last Modified: 12 Apr 2025

    Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain sensitive information or modify data via a JNAP action in a JNAP/ HTTP request.

    Published: 1 Nov 2014
    6.5
    Medium

    CVE-2014-8334

    Last Modified: 12 Apr 2025

    The WP-DBManager (aka Database Manager) plugin before 2.7.2 for WordPress allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) $backup['filepath'] (aka "Path to Backup:" field) or (2) $backup['mysqldumppath'] variable.

    Published: 31 Oct 2014
    4.3
    Medium

    CVE-2014-2334

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.

    Published: 31 Oct 2014
    4.3
    Medium

    CVE-2014-2335

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.

    Published: 31 Oct 2014
    4.3
    Medium

    CVE-2014-2336

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2334 and CVE-2014-2335.

    Published: 31 Oct 2014
    5
    Medium

    CVE-2014-8495

    Last Modified: 12 Apr 2025

    Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows context-dependent attackers to obtain sensitive information by reading the cache.

    Published: 31 Oct 2014
    4.3
    Medium

    CVE-2014-8577

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Contact][title] parameter to admin/contacts/contacts/add page; (2) data[Block][title] or (3) data[Block][alias] parameter to admin/blocks/blocks/edit page; (4) data[Region][title] parameter to admin/blocks/regions/add page; (5) data[Menu][title] or (6) data[Menu][alias] parameter to admin/menus/menus/add page; or (7) data[Link][title] parameter to admin/menus/links/add/menu page.

    Published: 31 Oct 2014
    4
    Medium

    CVE-2014-7177

    Last Modified: 12 Apr 2025

    XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.

    Published: 31 Oct 2014
    10
    Critical

    CVE-2014-7985

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in EspoCRM before 2.6.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter to install/index.php.

    Published: 31 Oct 2014
    5
    Medium

    CVE-2014-7986

    Last Modified: 12 Apr 2025

    install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.

    Published: 31 Oct 2014
    4.3
    Medium

    CVE-2014-7987

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in EspoCRM before 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the desc parameter in an errors action to install/index.php.

    Published: 31 Oct 2014