CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2014-6352

    Last Modified: 22 Apr 2026

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014 with a crafted PowerPoint document.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-8762

    Last Modified: 12 Apr 2025

    The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-8761

    Last Modified: 12 Apr 2025

    inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.

    Published: 22 Oct 2014
    6.8
    Medium

    CVE-2013-7407

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 22 Oct 2014
    7.8
    High

    CVE-2014-8325

    Last Modified: 12 Apr 2025

    The Calendar Base (cal) extension before 1.5.9 and 1.6.x before 1.6.1 for TYPO3 allows remote attackers to cause a denial of service (resource consumption) via vectors related to the PHP PCRE library.

    Published: 22 Oct 2014
    4.3
    Medium

    CVE-2014-8381

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Megapolis.Portal Manager allow remote attackers to inject arbitrary web script or HTML via the (1) dateFrom or (2) dateTo parameter.

    Published: 22 Oct 2014
    4.3
    Medium

    CVE-2014-7182

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker action in the wp-google-maps-menu page to wp-admin/admin.php.

    Published: 22 Oct 2014
    4.3
    Medium

    CVE-2014-7183

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query parameter or (2) QUERY_STRING.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-8763

    Last Modified: 12 Apr 2025

    DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-8764

    Last Modified: 12 Apr 2025

    DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-6387

    Last Modified: 12 Apr 2025

    gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-8088

    Last Modified: 12 Apr 2025

    The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.

    Published: 22 Oct 2014
    1.9
    Low

    CVE-2014-4448

    Last Modified: 12 Apr 2025

    House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.

    Published: 22 Oct 2014
    6.8
    Medium

    CVE-2014-4449

    Last Modified: 12 Apr 2025

    iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Oct 2014
    1.9
    Low

    CVE-2014-4450

    Last Modified: 12 Apr 2025

    The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-3695

    Last Modified: 12 Apr 2025

    markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a large length value in an emoticon response.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-3703

    Last Modified: 12 Apr 2025

    OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration option when generating the nova.conf configuration, which causes the firewall to be disabled and allows remote attackers to bypass intended access restrictions.

    Published: 22 Oct 2014
    6.4
    Medium

    CVE-2014-3694

    Last Modified: 12 Apr 2025

    The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-3712

    Last Modified: 12 Apr 2025

    Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils function in content_search_controller.rb or (2) action parameter in the respond function in api/api_controller.rb in app/controllers/katello/, which is passed to the to_sym method.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-3696

    Last Modified: 12 Apr 2025

    nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via a crafted server message that triggers a large memory allocation.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-3698

    Last Modified: 12 Apr 2025

    The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sensitive information from process memory via a crafted XMPP message.

    Published: 22 Oct 2014
    5
    Medium

    CVE-2014-3710

    Last Modified: 12 Apr 2025

    The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.

    Published: 22 Oct 2014
    6.5
    Medium

    CVE-2014-2531

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) Resellers interface, as demonstrated by the "or" key in a pgn8state object in an i object in a JSON object.

    Published: 21 Oct 2014
    3.5
    Low

    CVE-2014-3111

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27 through 0.32 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Printer Model field to the Printer Management page, (2) Image Name field to the Image Management page, (3) Storage Group Name field to the Storage Management page, (4) Username field to the User Cleanup FOG Configuration page, or (5) Directory Path field to the Directory Cleaner FOG Configuration page.

    Published: 21 Oct 2014
    3.5
    Low

    CVE-2014-8376

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the context administration sub-panel in the Site Banner module before 7.x-4.1 for Drupal allows remote authenticated users with the "Administer contexts" Context UI module permission to inject arbitrary web script or HTML via vectors related to context settings.

    Published: 21 Oct 2014
    4.3
    Medium

    CVE-2014-8377

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Webasyst Shop-Script 5.2.2.30933 allows remote attackers to inject arbitrary web script or HTML via the phone number field in a new contact to phpecom/index.php/webasyst/contacts/.

    Published: 21 Oct 2014
    5
    Medium

    CVE-2014-4577

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in reviews.php in the WP AmASIN - The Amazon Affiliate Shop plugin 0.9.6 and earlier for WordPress allows remote attackers to read arbitrary files via a full pathname in the url parameter.

    Published: 21 Oct 2014
    4.3
    Medium

    CVE-2014-4514

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to the getDebugInfo function.

    Published: 21 Oct 2014
    4.3
    Medium

    CVE-2014-4517

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in getNetworkSites.php in the CBI Referral Manager plugin 1.2.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the searchString parameter.

    Published: 21 Oct 2014
    7.5
    High

    CVE-2014-5005

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.

    Published: 21 Oct 2014
    7.5
    High

    CVE-2014-5006

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader.

    Published: 21 Oct 2014
    4.3
    Medium

    CVE-2014-7280

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web servers to inject arbitrary web script or HTML via the server header.

    Published: 21 Oct 2014
    3.5
    Low

    CVE-2014-8378

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the TableField module 7.x-2.x before 7.x-2.3 allows remote authenticated users with the "administer content types" or "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related to the field help text in an entity edit form.

    Published: 21 Oct 2014
    3.5
    Low

    CVE-2014-8379

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Marketo MA module before 7.x-1.5 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to field titles to the (1) Webform or (2) User sub-modules.

    Published: 21 Oct 2014
    4.3
    Medium

    CVE-2014-8380

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer Header in a "404 Not Found" response. NOTE: this vulnerability might exist because of a CVE-2010-2429 regression.

    Published: 21 Oct 2014
    6.5
    Medium

    CVE-2014-8375

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php.

    Published: 21 Oct 2014
    5
    Medium

    CVE-2012-5243

    Last Modified: 12 Apr 2025

    functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

    Published: 21 Oct 2014
    4.3
    Medium

    CVE-2012-5702

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to index.php. NOTE: the date parameter vector is already covered by CVE-2008-3886.

    Published: 21 Oct 2014
    7.5
    High

    CVE-2013-7406

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Oct 2014
    7.5
    High

    CVE-2014-7140

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the management interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.x before 10.1-129.11 and 10.5 before 10.5-50.10 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 21 Oct 2014
    6.8
    Medium

    CVE-2012-5242

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7762

    Last Modified: 12 Apr 2025

    The Bite it! (aka com.ASA1Touch.Bite_it) application 1.1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7763

    Last Modified: 12 Apr 2025

    The Listen up! mirucho (aka jp.ameba.kiiteyo.android) application 1.1.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7764

    Last Modified: 12 Apr 2025

    The Semper Invicta Fitness (aka com.semper.invicta.fitness) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7765

    Last Modified: 12 Apr 2025

    The Hundred Thousands Kid Book (aka it.tinytap.attsa.thousands) application 1.6.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7766

    Last Modified: 12 Apr 2025

    The 7 Habits Personal Development (aka appinventor.ai_ingka_d_jiw.TheCompleteGuideToApplyingThe7HabitsInHolisticPersonalDevelopment) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7767

    Last Modified: 12 Apr 2025

    The A+ (aka cn.xrzcm) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7773

    Last Modified: 12 Apr 2025

    The Cleveland Football STREAM (aka com.appstronautme.clevelandfootballstream) application 2.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7774

    Last Modified: 12 Apr 2025

    The Herbs & Flowers Dictionary (aka com.wHerbsNFlowersDictionary) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7775

    Last Modified: 12 Apr 2025

    The Champak - Hindi (aka com.magzter.champakhindi) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014