CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2014-6506

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Published: 14 Oct 2014
    5
    Medium

    CVE-2014-6511

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20 allows remote attackers to affect confidentiality via unknown vectors related to 2D.

    Published: 14 Oct 2014
    4.3
    Medium

    CVE-2014-6512

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Libraries.

    Published: 14 Oct 2014
    4.3
    Medium

    CVE-2014-6531

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Libraries.

    Published: 14 Oct 2014
    9.3
    Critical

    CVE-2014-6532

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4288, CVE-2014-6493, and CVE-2014-6503.

    Published: 14 Oct 2014
    9.8
    Critical

    CVE-2014-3585

    Last Modified: 21 Nov 2024

    redhat-upgrade-tool: Does not check GPG signatures when upgrading versions

    Published: 14 Oct 2014
    6
    Medium

    CVE-2014-3593

    Last Modified: 12 Apr 2025

    Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted cluster configuration.

    Published: 14 Oct 2014
    5
    Medium

    CVE-2014-3668

    Last Modified: 12 Apr 2025

    Buffer overflow in the date_from_ISO8601 function in the mkgmtime implementation in libxmlrpc/xmlrpc.c in the XMLRPC extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) via (1) a crafted first argument to the xmlrpc_set_type function or (2) a crafted argument to the xmlrpc_decode function, related to an out-of-bounds read operation.

    Published: 14 Oct 2014
    6.8
    Medium

    CVE-2014-3670

    Last Modified: 12 Apr 2025

    The exif_ifd_make_value function in exif.c in the EXIF extension in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 operates on floating-point arrays incorrectly, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a crafted JPEG image with TIFF thumbnail data that is improperly handled by the exif_thumbnail function.

    Published: 14 Oct 2014
    9.3
    Critical

    CVE-2014-6456

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Oct 2014
    6.8
    Medium

    CVE-2014-6468

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u20 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

    Published: 14 Oct 2014
    5
    Medium

    CVE-2014-6476

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-6527.

    Published: 14 Oct 2014
    7.6
    High

    CVE-2014-6493

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2014-4288, CVE-2014-6503, and CVE-2014-6532.

    Published: 14 Oct 2014
    5
    Medium

    CVE-2014-6504

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot.

    Published: 14 Oct 2014
    10
    Critical

    CVE-2014-6513

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.

    Published: 14 Oct 2014
    5
    Medium

    CVE-2014-6515

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20 allows remote attackers to affect integrity via unknown vectors related to Deployment.

    Published: 14 Oct 2014
    5
    Medium

    CVE-2014-6517

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and Jrockit R27.8.3 and R28.3.3 allows remote attackers to affect confidentiality via vectors related to JAXP.

    Published: 14 Oct 2014
    2.6
    Low

    CVE-2014-6527

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect integrity via unknown vectors related to Deployment, a different vulnerability than CVE-2014-6476.

    Published: 14 Oct 2014
    2.6
    Low

    CVE-2014-6558

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and JRockit R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Security.

    Published: 14 Oct 2014
    9.3
    Critical

    CVE-2014-6562

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u20 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Published: 14 Oct 2014
    9.8
    Critical

    CVE-2014-9766

    Last Modified: 12 Apr 2025

    Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and stride values.

    Published: 14 Oct 2014
    3.5
    Low

    CVE-2014-8743

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Maestro module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) Role or (2) Organic Group name.

    Published: 13 Oct 2014
    Unknown

    CVE-2014-6915

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-7046, CVE-2014-7047. Reason: this ID was intended for one issue, but was assigned to two issues by a CNA. Notes: All CVE users should consult CVE-2014-7046 and CVE-2014-7047 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Oct 2014
    3.5
    Low

    CVE-2014-8744

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Nivo Slider module 7.x-2.x before 7.x-1.11 for Drupal allows remote authenticated users with the "administer nivo slider" permission to inject arbitrary web script or HTML via an image title.

    Published: 13 Oct 2014
    Unknown

    CVE-2014-3671

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187. Reason: This candidate is a duplicate of CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, and CVE-2014-7187. Notes: All CVE users should reference CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, and CVE-2014-7187 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Oct 2014
    Unknown

    CVE-2014-6388

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3634. Reason: This candidate is a reservation duplicate of CVE-2014-3634. Notes: All CVE users should reference CVE-2014-3634 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Oct 2014
    3.5
    Low

    CVE-2014-8745

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.13 and 7.x-1.x before 7.x-1.15 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary label.

    Published: 13 Oct 2014
    3.5
    Low

    CVE-2014-8746

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Skeleton theme 7.x-1.2 through 7.x-1.3 before 7.x-1.4, for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.

    Published: 13 Oct 2014
    4.3
    Medium

    CVE-2014-8747

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Drupal Commons module 7.x-3.x before 7.x-3.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to content creation and activity stream messages.

    Published: 13 Oct 2014
    3.5
    Low

    CVE-2014-8748

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Google Doubleclick for Publishers (DFP) module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer dfp" permission to inject arbitrary web script or HTML via a slot name.

    Published: 13 Oct 2014
    10
    Critical

    CVE-2014-7297

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the folder framework in the Enfold theme before 3.0.1 for WordPress has unknown impact and attack vectors.

    Published: 13 Oct 2014
    5
    Medium

    CVE-2014-1572

    Last Modified: 12 Apr 2025

    The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.

    Published: 13 Oct 2014
    4
    Medium

    CVE-2014-1571

    Last Modified: 12 Apr 2025

    Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.

    Published: 13 Oct 2014
    4.3
    Medium

    CVE-2014-1573

    Last Modified: 12 Apr 2025

    Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.

    Published: 13 Oct 2014
    5
    Medium

    CVE-2014-3091

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.1.x and 7.2.x allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 13 Oct 2014
    5
    Medium

    CVE-2014-3675

    Last Modified: 12 Apr 2025

    Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

    Published: 13 Oct 2014
    7.5
    High

    CVE-2014-3676

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."

    Published: 13 Oct 2014
    7.5
    High

    CVE-2014-3677

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.

    Published: 13 Oct 2014
    4.9
    Medium

    CVE-2014-8480

    Last Modified: 12 Apr 2025

    The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 lacks intended decoder-table flags for certain RIP-relative instructions, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a crafted application.

    Published: 13 Oct 2014
    4.9
    Medium

    CVE-2014-8481

    Last Modified: 12 Apr 2025

    The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 does not properly handle invalid instructions, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via a crafted application that triggers (1) an improperly fetched instruction or (2) an instruction that occupies too many bytes. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8480.

    Published: 13 Oct 2014
    6.8
    Medium

    CVE-2014-5327

    Last Modified: 12 Apr 2025

    Buffer overflow in the Webserver component on the Huawei E5332 router before 21.344.27.00.1080 allows remote authenticated users to cause a denial of service (reboot) via a long URI.

    Published: 12 Oct 2014
    6.8
    Medium

    CVE-2014-5328

    Last Modified: 12 Apr 2025

    Buffer overflow in the Webserver component on the Huawei E5332 router before 21.344.27.00.1080 allows remote authenticated users to cause a denial of service (reboot) via a long parameter in an API service request message.

    Published: 12 Oct 2014
    5
    Medium

    CVE-2014-3583

    Last Modified: 12 Apr 2025

    The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.

    Published: 12 Oct 2014
    10
    Critical

    CVE-2014-3692

    Last Modified: 12 Apr 2025

    The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote attackers to gain privileges.

    Published: 12 Oct 2014
    8.8
    High

    CVE-2014-9765

    Last Modified: 12 Apr 2025

    Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.

    Published: 12 Oct 2014
    5.4
    Medium

    CVE-2014-6938

    Last Modified: 12 Apr 2025

    The Apostilas musicais (aka com.apostilas) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Oct 2014
    5.4
    Medium

    CVE-2014-6939

    Last Modified: 12 Apr 2025

    The Sketch W Friends FREE -Tablets (aka air.com.xlabz.SketchWFriendsFree) application 5.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Oct 2014
    5.4
    Medium

    CVE-2014-6891

    Last Modified: 12 Apr 2025

    The Vodafone Avantaj Cepte (aka com.vodafone.avantajcepte.main) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Oct 2014
    5.4
    Medium

    CVE-2014-6940

    Last Modified: 12 Apr 2025

    The Absolute Lending Solutions (aka com.soln.S008F6C05EC0B63264B429F6D76286562) application 1.0073.b0073 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Oct 2014
    5.4
    Medium

    CVE-2014-6887

    Last Modified: 12 Apr 2025

    The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Oct 2014