CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-7757

    Last Modified: 12 Apr 2025

    The Awful Ninja Game (aka com.absolutelyawfulapplications.awfulninjagame) application 1.0.23 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7758

    Last Modified: 12 Apr 2025

    The AMKAMAL Science Portfolio (aka com.wAMKAMALSciencePortfolio) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.4
    Medium

    CVE-2014-7759

    Last Modified: 12 Apr 2025

    The Jazz Lovers Radio (aka com.nobexinc.wls_99273254.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 21 Oct 2014
    5.5
    Medium

    CVE-2014-3610

    Last Modified: 12 Apr 2025

    The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and the handle_wrmsr function in arch/x86/kvm/vmx.c.

    Published: 21 Oct 2014
    5
    Medium

    CVE-2014-3569

    Last Modified: 12 Apr 2025

    The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, and 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unexpected handshake, as demonstrated by an SSLv3 handshake to a no-ssl3 application with certain error handling. NOTE: this issue became relevant after the CVE-2014-3568 fix.

    Published: 21 Oct 2014
    4.7
    Medium

    CVE-2014-3611

    Last Modified: 12 Apr 2025

    Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation.

    Published: 21 Oct 2014
    5.5
    Medium

    CVE-2014-3646

    Last Modified: 12 Apr 2025

    arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

    Published: 21 Oct 2014
    5.5
    Medium

    CVE-2014-3647

    Last Modified: 12 Apr 2025

    arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

    Published: 21 Oct 2014
    5.5
    Medium

    CVE-2014-3690

    Last Modified: 12 Apr 2025

    arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm access, as demonstrated by PR_SET_TSC prctl calls within a modified copy of QEMU.

    Published: 21 Oct 2014
    2.1
    Low

    CVE-2014-3645

    Last Modified: 12 Apr 2025

    arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.12 does not have an exit handler for the INVEPT instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.

    Published: 21 Oct 2014
    7.5
    High

    CVE-2014-3651

    Last Modified: 20 Apr 2025

    JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/qrcode, related to QR code generation.

    Published: 21 Oct 2014
    6.1
    Medium

    CVE-2014-3652

    Last Modified: 21 Nov 2024

    JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.

    Published: 21 Oct 2014
    6.1
    Medium

    CVE-2014-3656

    Last Modified: 21 Nov 2024

    JBoss KeyCloak: XSS in login-status-iframe.html

    Published: 21 Oct 2014
    8.8
    High

    CVE-2014-3709

    Last Modified: 20 Apr 2025

    The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.

    Published: 21 Oct 2014
    4.3
    Medium

    CVE-2014-8365

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Xornic Contact Us allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) email parameter to contact.php or (3) PATH_INFO to setup.php, related to the "PHP_SELF" variable.

    Published: 20 Oct 2014
    4.3
    Medium

    CVE-2014-3863

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the JChatSocial component before 2.3 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the filename parameter in a file upload in an active JChat chat window.

    Published: 20 Oct 2014
    7.5
    High

    CVE-2014-8366

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in openSIS 4.5 through 5.3 allows remote attackers to execute arbitrary SQL commands via the Username and password to index.php.

    Published: 20 Oct 2014
    3.5
    Low

    CVE-2014-5025

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.

    Published: 20 Oct 2014
    3.5
    Low

    CVE-2014-5026

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input Method Name, or (5) Host Templates Name in a delete action; (6) Data Source Title; (7) Graph Title; or (8) Graph Template Name in a delete or (9) duplicate action.

    Published: 20 Oct 2014
    4.3
    Medium

    CVE-2014-8364

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ss_id parameter.

    Published: 20 Oct 2014
    3.5
    Low

    CVE-2014-5169

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Date module before 7.x-2.8 for Drupal allows remote authenticated users with the permission to create a date field to inject arbitrary web script or HTML via the date field title.

    Published: 20 Oct 2014
    7.5
    High

    CVE-2014-8363

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.

    Published: 20 Oct 2014
    3.5
    Low

    CVE-2014-5276

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php.

    Published: 20 Oct 2014
    6.5
    Medium

    CVE-2014-5275

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter.

    Published: 20 Oct 2014
    6.8
    Medium

    CVE-2012-5694

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allow remote attackers to execute arbitrary SQL commands via the (1) agentPhNo, (2) controlPhNo, (3) agentURLPath, (4) agentControlKey, or (5) platformDD1 parameter to frameworkgui/attach2Agents.pl; the (6) modemPhoneNo, (7) controlKey, or (8) appURLPath parameter to frameworkgui/attachMobileModem.pl; the agentsDD parameter to (9) escalatePrivileges.pl, (10) getContacts.pl, (11) getDatabase.pl, (12) sendSMS.pl, or (13) takePic.pl in frameworkgui/; or the modemNoDD parameter to (14) escalatePrivileges.pl, (15) getContacts.pl, (16) getDatabase.pl, (17) SEAttack.pl, (18) sendSMS.pl, (19) takePic.pl, or (20) CSAttack.pl in frameworkgui/.

    Published: 20 Oct 2014
    4.6
    Medium

    CVE-2012-5697

    Last Modified: 12 Apr 2025

    The btinstall installation script in Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 uses weak permissions (777) for all files in the frameworkgui/ directory, which allows local users to obtain sensitive information or inject arbitrary Perl code via direct access to these files.

    Published: 20 Oct 2014
    5
    Medium

    CVE-2012-5696

    Last Modified: 12 Apr 2025

    Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers to obtain the plaintext database password via a direct request.

    Published: 20 Oct 2014
    4.3
    Medium

    CVE-2014-3830

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in info.php in TomatoCart 1.1.8.6.1 allows remote attackers to inject arbitrary web script or HTML via the faqs_id parameter.

    Published: 20 Oct 2014
    6.5
    Medium

    CVE-2014-3978

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands via the First Name and Last Name fields in a new address book contact.

    Published: 20 Oct 2014
    3.5
    Low

    CVE-2014-8330

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account.

    Published: 20 Oct 2014
    6.8
    Medium

    CVE-2014-8331

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3236 before E3276sTCPU-V200R002B470D13SP00C00 and E3276sWebUI-V100R007B100D03SP01C03 and E3276 before E3236sTCPU-V200R002B146D41SP00C00 and E3236sWebUI-V100R007B100D03SP01C03 allow remote attackers to hijack the authentication of administrators for requests that (1) change configuration settings or (2) use device functions.

    Published: 20 Oct 2014
    6.8
    Medium

    CVE-2012-5695

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allow remote attackers to hijack the authentication of administrators for requests that conduct (1) shell metacharacter or (2) SQL injection attacks or (3) send an SMS message.

    Published: 20 Oct 2014
    4.3
    Medium

    CVE-2014-5098

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Search module before 1.2.2 in Jamroom allows remote attackers to inject arbitrary web script or HTML via the query string to search/results/.

    Published: 20 Oct 2014
    7.5
    High

    CVE-2014-2081

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua before 2013.2.4 and 2014.x before 2014.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

    Published: 20 Oct 2014
    6.8
    Medium

    CVE-2012-5701

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search_string or (2) where parameter in a contacts action, (3) dept_id parameter in a departments action, (4) project_id[] parameter in a project action, or (5) company_id parameter in a system action to index.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

    Published: 20 Oct 2014
    4.3
    Medium

    CVE-2012-5866

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in include.php in Achievo 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter.

    Published: 20 Oct 2014
    5
    Medium

    CVE-2014-5094

    Last Modified: 12 Apr 2025

    Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function.

    Published: 20 Oct 2014
    2.1
    Low

    CVE-2014-5447

    Last Modified: 12 Apr 2025

    Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.

    Published: 20 Oct 2014
    2.1
    Low

    CVE-2014-5448

    Last Modified: 12 Apr 2025

    Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by reading the log files.

    Published: 20 Oct 2014
    2.1
    Low

    CVE-2014-5449

    Last Modified: 12 Apr 2025

    Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.

    Published: 20 Oct 2014
    10
    Critical

    CVE-2014-8329

    Last Modified: 12 Apr 2025

    Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for the ftp and telnet services via a direct request for ZTPUsrDtls.txt.

    Published: 20 Oct 2014
    6.5
    Medium

    CVE-2012-5865

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL commands via the activityid parameter in a stats action.

    Published: 20 Oct 2014
    4.3
    Medium

    CVE-2014-6280

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in OSClass before 3.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) action or (2) nsextt parameter to oc-admin/index.php or the (3) nsextt parameter in an items_reported action to oc-admin/index.php.

    Published: 20 Oct 2014
    5
    Medium

    CVE-2014-6308

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter in a render action to oc-admin/index.php.

    Published: 20 Oct 2014
    4.3
    Medium

    CVE-2012-2413

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ja_purity template for Joomla! 1.5.26 and earlier allows remote attackers to inject arbitrary web script or HTML via the Mod* cookie parameter to html/modules.php.

    Published: 20 Oct 2014
    7.5
    High

    CVE-2012-5244

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) return, (2) display, (3) table, or (4) search parameter to functions/suggest.php; (5) the id parameter to functions/widgets.php, (6) the category parameter to functions/print.php; or (7) the name parameter to functions/ajax.php.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7491

    Last Modified: 12 Apr 2025

    The Short Stories (aka com.ireadercity.c48) application 3.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7517

    Last Modified: 12 Apr 2025

    The Myanmar Movies HD (aka com.wmyanmarmoviesHD) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7525

    Last Modified: 12 Apr 2025

    The Domain Name Search & Web Host (aka com.wDomainNameSearchandRegistration) application 0.64.13398.55733 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014
    5.4
    Medium

    CVE-2014-7533

    Last Modified: 12 Apr 2025

    The NotreDame Seguradora (aka br.com.notredame.mobile.NotreDame) application 1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 20 Oct 2014