CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2014-8308

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Send to Inbox functionality in SAP BusinessObjects BI EDGE 4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Oct 2014
    5
    Medium

    CVE-2014-8309

    Last Modified: 12 Apr 2025

    SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames via SecEnterprise authentication requests to the Session web service.

    Published: 16 Oct 2014
    7.1
    High

    CVE-2014-8310

    Last Modified: 12 Apr 2025

    The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFactory::Session ORB message.

    Published: 16 Oct 2014
    3.5
    Low

    CVE-2014-8311

    Last Modified: 12 Apr 2025

    SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information via an InfoStore query to a CORBA listener.

    Published: 16 Oct 2014
    4.3
    Medium

    CVE-2014-8296

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Modal Frame API module 6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Oct 2014
    6.1
    Medium

    CVE-2014-10401

    Last Modified: 21 Nov 2024

    An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.

    Published: 16 Oct 2014
    5
    Medium

    CVE-2014-3660

    Last Modified: 12 Apr 2025

    parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing a large number of nested entity references, a variant of the "billion laughs" attack.

    Published: 16 Oct 2014
    7.5
    High

    CVE-2014-3704

    Last Modified: 12 Apr 2025

    The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

    Published: 16 Oct 2014
    6.8
    Medium

    CVE-2014-7237

    Last Modified: 12 Apr 2025

    lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and upload files with restricted names via a null byte (%00) in a filename to bin/upload.cgi, as demonstrated using .htaccess to execute arbitrary code.

    Published: 16 Oct 2014
    3.3
    Low

    CVE-2014-9680

    Last Modified: 20 Apr 2025

    sudo before 1.8.12 does not ensure that the TZ environment variable is associated with a zoneinfo file, which allows local users to open arbitrary files for read access (but not view file contents) by running a program within an sudo session, as demonstrated by interfering with terminal output, discarding kernel-log messages, or repositioning tape drives.

    Published: 16 Oct 2014
    8.1
    High

    CVE-2014-5282

    Last Modified: 21 Nov 2024

    Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.

    Published: 16 Oct 2014
    3.5
    Low

    CVE-2014-6487

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote authenticated users to affect integrity via unknown vectors related to End User Self Service.

    Published: 15 Oct 2014
    5
    Medium

    CVE-2014-6498

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, 6.3.4, and 6.3.5 allows remote attackers to affect confidentiality via unknown vectors related to Security.

    Published: 15 Oct 2014
    6.5
    Medium

    CVE-2014-6537

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Oct 2014
    3.6
    Low

    CVE-2014-6543

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to ITEM (Item & BOM).

    Published: 15 Oct 2014
    9
    Critical

    CVE-2014-6545

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6453, CVE-2014-6467, and CVE-2014-6560.

    Published: 15 Oct 2014
    9
    Critical

    CVE-2014-6546

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6552

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to affect integrity via unknown vectors related to Admin Console.

    Published: 15 Oct 2014
    2.1
    Low

    CVE-2014-6488

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform: 10.2.0.5, 11.1.0.1 EM DB Control: 11.1.0.7, 11.2.0.3, 11.2.0.4 EM Plugin for DB: 12.1.0.4, 12.1.0.5, and 12.1.0.6 allows remote authenticated users to affect integrity via unknown vectors related to Content Management.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-6523

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality via vectors related to REST Interface.

    Published: 15 Oct 2014
    3.6
    Low

    CVE-2014-6544

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JDBC component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2014-4289.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-6547

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4293, CVE-2014-4296, CVE-2014-4297, CVE-2014-4310, and CVE-2014-6477.

    Published: 15 Oct 2014
    6.4
    Medium

    CVE-2014-6553

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5 and 11.1.1.7 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Admin Console.

    Published: 15 Oct 2014
    9
    Critical

    CVE-2014-6560

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2014-6453, CVE-2014-6467, and CVE-2014-6545.

    Published: 15 Oct 2014
    6.8
    Medium

    CVE-2014-6533

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1 and 6.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-6534

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0 allows remote authenticated users to affect integrity via vectors related to WLS Console.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-6486

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect integrity via unknown vectors related to Talent Acquisition Manager - Security.

    Published: 15 Oct 2014
    2.1
    Low

    CVE-2014-6501

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via vectors related to SSH.

    Published: 15 Oct 2014
    5
    Medium

    CVE-2014-6490

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability via vectors related to SMB server user component.

    Published: 15 Oct 2014
    4.9
    Medium

    CVE-2014-6497

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors related to Kernel.

    Published: 15 Oct 2014
    6.8
    Medium

    CVE-2014-6499

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to WebLogic Tuxedo Connector.

    Published: 15 Oct 2014
    7.8
    High

    CVE-2014-6508

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via vectors related to iSCSI Data Mover (IDM).

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6516

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 8.98 allows local users to affect confidentiality, integrity, and availability via vectors related to Installation SEC.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6522

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.1.7, 11.1.2.4, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect integrity via vectors related to ADF Faces.

    Published: 15 Oct 2014
    6.8
    Medium

    CVE-2014-6529

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hermon HCA PCIe driver.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-6542

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4298, CVE-2014-4299, CVE-2014-4300, CVE-2014-6452, and CVE-2014-6454.

    Published: 15 Oct 2014
    5.8
    Medium

    CVE-2014-6535

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52, 8.53, and 8.54 allows remote attackers to affect confidentiality and integrity via vectors related to SECURITY.

    Published: 15 Oct 2014
    3.5
    Low

    CVE-2014-6536

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Security.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-6538

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4294, CVE-2014-4295, and CVE-2014-6563.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6539

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via vectors related to LOV, a different vulnerability than CVE-2014-6472.

    Published: 15 Oct 2014
    1.9
    Low

    CVE-2014-6540

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.34, before 4.2.26, and before 4.3.14 allows local users to affect availability via vectors related to Graphics driver (WDDM) for Windows guests.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6550

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to iHelp.

    Published: 15 Oct 2014
    5.5
    Medium

    CVE-2014-6554

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.1 and 11.1.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Admin Console.

    Published: 15 Oct 2014
    4.9
    Medium

    CVE-2014-6557

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Application Performance Management component in Oracle Enterprise Manager Grid Control before 12.1.0.6.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to End User Experience Management.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6561

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Payments component in Oracle E-Business Suite 12.0.4, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via unknown vectors related to Separate Remittance Advice.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-6563

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4294, CVE-2014-4295, and CVE-2014-6538.

    Published: 15 Oct 2014
    5
    Medium

    CVE-2014-2473

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.0 and 5.1 allows remote attackers to affect availability via vectors related to SGD Proxy Server (ttaauxserv) and SGD SSL Daemon (ttassl).

    Published: 15 Oct 2014
    4.9
    Medium

    CVE-2014-4275

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via vectors related to SMB server kernel module.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-4290

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4291, CVE-2014-4292, CVE-2014-4293, CVE-2014-4296, CVE-2014-4297, CVE-2014-4310, CVE-2014-6547, and CVE-2014-6477.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-4294

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4295, CVE-2014-6538, and CVE-2014-6563.

    Published: 15 Oct 2014