CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2014-6312

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before 3.2.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the custom_style_afo parameter on the login_widget_afo page to wp-admin/options-general.php.

    Published: 15 Oct 2014
    3.6
    Low

    CVE-2014-7206

    Last Modified: 12 Apr 2025

    The changelog command in Apt before 1.0.9.2 allows local users to write to arbitrary files via a symlink attack on the changelog file.

    Published: 15 Oct 2014
    8.8
    High

    CVE-2014-4123

    Last Modified: 21 Apr 2026

    Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.

    Published: 15 Oct 2014
    7.8
    High

    CVE-2014-4114

    Last Modified: 22 Apr 2026

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."

    Published: 15 Oct 2014
    8.8
    High

    CVE-2014-4148

    Last Modified: 22 Apr 2026

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."

    Published: 15 Oct 2014
    7.8
    High

    CVE-2014-4113

    Last Modified: 22 Apr 2026

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6952

    Last Modified: 12 Apr 2025

    The Manga Facts (aka app.mangafacts.ar) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6951

    Last Modified: 12 Apr 2025

    The OneFile Ignite (aka uk.co.onefile.ignite) application 1.19 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6950

    Last Modified: 12 Apr 2025

    The Mt. Airy News (aka com.soln.SBE4A803AD6430A6E9DBA5688AA644148) application 1.0069.b0069 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6947

    Last Modified: 12 Apr 2025

    The Archie Comics (aka com.iversecomics.archie.android) application 1.07 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    7.2
    High

    CVE-2014-4115

    Last Modified: 12 Apr 2025

    fastfat.sys (aka the FASTFAT driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 does not properly allocate memory, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (reserved-memory write) by connecting a crafted USB device, aka "Microsoft Windows Disk Partition Driver Elevation of Privilege Vulnerability."

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-4122

    Last Modified: 12 Apr 2025

    Microsoft .NET Framework 2.0 SP2, 3.5, and 3.5.1 omits the ASLR protection mechanism, which allows remote attackers to obtain potentially sensitive information about memory addresses by leveraging the predictability of an executable image's location, aka ".NET ASLR Vulnerability."

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6943

    Last Modified: 12 Apr 2025

    The Konigsleiten (aka com.knigsleiten) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6948

    Last Modified: 12 Apr 2025

    The TH3 professional Al Mohtarif (aka com.th3professional.almohtarif) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4133

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4137.

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4134

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4137

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4133.

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4138

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4130 and CVE-2014-4132.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-4140

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4141

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 15 Oct 2014
    6.8
    Medium

    CVE-2014-0570

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-0571

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Oct 2014
    4.6
    Medium

    CVE-2014-0572

    Last Modified: 12 Apr 2025

    Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows local users to bypass intended IP-based access restrictions via unspecified vectors.

    Published: 15 Oct 2014
    10
    Critical

    CVE-2014-4073

    Last Modified: 12 Apr 2025

    Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, which allows remote attackers to gain privileges via vectors involving Internet Explorer, aka ".NET ClickOnce Elevation of Privilege Vulnerability."

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4117

    Last Modified: 12 Apr 2025

    Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 allow remote attackers to execute arbitrary code via crafted properties in a Word document, aka "Microsoft Word File Format Vulnerability."

    Published: 15 Oct 2014
    6.8
    Medium

    CVE-2014-4124

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-4123.

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6949

    Last Modified: 12 Apr 2025

    The Akne Ernahrung (aka com.rareartifact.akneernahrung72010074) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-4075

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in System.Web.Mvc.dll in Microsoft ASP.NET Model View Controller (MVC) 2.0 through 5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted web page, aka "MVC XSS Vulnerability."

    Published: 15 Oct 2014
    10
    Critical

    CVE-2014-4121

    Last Modified: 12 Apr 2025

    Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly parse internationalized resource identifiers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted request to a .NET web application, aka ".NET Framework Remote Code Execution Vulnerability."

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4132

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4130 and CVE-2014-4138.

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4126

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4127

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4128

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4129

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 15 Oct 2014
    9.3
    Critical

    CVE-2014-4130

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4132 and CVE-2014-4138.

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6942

    Last Modified: 12 Apr 2025

    The Alisha Marie (Unofficial) (aka com.automon.ay.alisha.marie) application 1.4.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6944

    Last Modified: 12 Apr 2025

    The mitfahrgelegenheit.at (aka com.carpooling.android.at) application 2.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6945

    Last Modified: 12 Apr 2025

    The Neeku Naaku Dash Dash (aka com.dakshaa.nndd) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    5.4
    Medium

    CVE-2014-6946

    Last Modified: 12 Apr 2025

    The Re:kyu (aka com.appzone619) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Oct 2014
    6.5
    Medium

    CVE-2014-6555

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6559

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.

    Published: 15 Oct 2014
    7.1
    High

    CVE-2014-3567

    Last Modified: 12 Apr 2025

    Memory leak in the tls_decrypt_ticket function in t1_lib.c in OpenSSL before 0.9.8zc, 1.0.0 before 1.0.0o, and 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memory consumption) via a crafted session ticket that triggers an integrity-check failure.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-4287

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:CHARACTER SETS.

    Published: 15 Oct 2014
    3.3
    Low

    CVE-2014-6463

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:REPLICATION ROW FORMAT BINARY LOG DML.

    Published: 15 Oct 2014
    6.8
    Medium

    CVE-2014-6469

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:OPTIMIZER.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6478

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL.

    Published: 15 Oct 2014
    5.5
    Medium

    CVE-2014-6489

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect integrity and availability via vectors related to SERVER:SP.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6494

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496.

    Published: 15 Oct 2014
    4.3
    Medium

    CVE-2014-6495

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.

    Published: 15 Oct 2014
    4
    Medium

    CVE-2014-6505

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to SERVER:MEMORY STORAGE ENGINE.

    Published: 15 Oct 2014