CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2014-7226

    Last Modified: 12 Apr 2025

    The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.

    Published: 10 Oct 2014
    7.5
    High

    CVE-2014-8240

    Last Modified: 12 Apr 2025

    Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-based buffer overflow, a similar issue to CVE-2014-6051.

    Published: 10 Oct 2014
    5.9
    Medium

    CVE-2014-0104

    Last Modified: 21 Nov 2024

    In fence-agents before 4.0.17 does not verify remote SSL certificates in the fence_cisco_ucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.

    Published: 10 Oct 2014
    9.8
    Critical

    CVE-2014-8241

    Last Modified: 12 Apr 2025

    XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.

    Published: 10 Oct 2014
    6.8
    Medium

    CVE-2014-3686

    Last Modified: 12 Apr 2025

    wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.

    Published: 10 Oct 2014
    3.5
    Low

    CVE-2014-8076

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Professional theme 7.x before 7.x-2.04 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to custom copyright information.

    Published: 9 Oct 2014
    3.5
    Low

    CVE-2014-8077

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the NewsFlash theme 6.x-1.x before 6.x-1.7 and 7.x-1.x before 7.x-2.5 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to font family CSS property.

    Published: 9 Oct 2014
    3.5
    Low

    CVE-2014-8075

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Tribune module 6.x-1.x and 7.x-3.x for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via a node title.

    Published: 9 Oct 2014
    3.5
    Low

    CVE-2014-8078

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 6.x-1.x before 6.x-1.19, 7.x-1.x before 7.x-1.3, and 7.x-2.x before 7.x-2.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes.

    Published: 9 Oct 2014
    4
    Medium

    CVE-2014-8079

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MAYO theme 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to header background setting.

    Published: 9 Oct 2014
    5
    Medium

    CVE-2014-8068

    Last Modified: 12 Apr 2025

    Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by book-navigation information.

    Published: 9 Oct 2014
    5
    Medium

    CVE-2014-8712

    Last Modified: 12 Apr 2025

    The build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 9 Oct 2014
    4.7
    Medium

    CVE-2014-8086

    Last Modified: 12 Apr 2025

    Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag.

    Published: 9 Oct 2014
    7.5
    High

    CVE-2014-3673

    Last Modified: 12 Apr 2025

    The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.

    Published: 9 Oct 2014
    7.5
    High

    CVE-2014-3687

    Last Modified: 12 Apr 2025

    The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.

    Published: 9 Oct 2014
    5
    Medium

    CVE-2014-3688

    Last Modified: 12 Apr 2025

    The SCTP implementation in the Linux kernel before 3.17.4 allows remote attackers to cause a denial of service (memory consumption) by triggering a large number of chunks in an association's output queue, as demonstrated by ASCONF probes, related to net/sctp/inqueue.c and net/sctp/sm_statefuns.c.

    Published: 9 Oct 2014
    5
    Medium

    CVE-2014-8713

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the build_expert_data function in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 9 Oct 2014
    4.3
    Medium

    CVE-2014-6631

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in com_media in Joomla! 3.2.x before 3.2.5 and 3.3.x before 3.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Oct 2014
    7.5
    High

    CVE-2014-6632

    Last Modified: 12 Apr 2025

    Joomla! 2.5.x before 2.5.25, 3.x before 3.2.4, and 3.3.x before 3.3.4 allows remote attackers to authenticate and bypass intended access restrictions via vectors involving LDAP authentication.

    Published: 8 Oct 2014
    4
    Medium

    CVE-2014-5375

    Last Modified: 12 Apr 2025

    The server in Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 does not properly validate the message owner matches the submitting user, which allows remote authenticated users to impersonate arbitrary users via the UserId and Owner tags.

    Published: 8 Oct 2014
    5
    Medium

    CVE-2014-5300

    Last Modified: 12 Apr 2025

    Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execute commands via a message without a signature.

    Published: 8 Oct 2014
    4
    Medium

    CVE-2014-5376

    Last Modified: 12 Apr 2025

    Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0, when a pre-generated key is used, does not validate that the requesting user matches the actor in the message, which allows remote authenticated users to impersonate arbitrary users via the actor field in a message.

    Published: 8 Oct 2014
    5
    Medium

    CVE-2014-7229

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Joomla! before 2.5.4 before 2.5.26, 3.x before 3.2.6, and 3.3.x before 3.3.5 allows attackers to cause a denial of service via unspecified vectors.

    Published: 8 Oct 2014
    6.8
    Medium

    CVE-2014-7296

    Last Modified: 12 Apr 2025

    The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.

    Published: 8 Oct 2014
    7.5
    High

    CVE-2014-7981

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 8 Oct 2014
    4.3
    Medium

    CVE-2014-7982

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Oct 2014
    4.3
    Medium

    CVE-2014-7983

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in com_contact in Joomla! CMS 3.1.2 through 3.2.x before 3.2.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Oct 2014
    7.5
    High

    CVE-2014-7984

    Last Modified: 12 Apr 2025

    Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving GMail authentication.

    Published: 8 Oct 2014
    3.5
    Low

    CVE-2014-7979

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.

    Published: 8 Oct 2014
    3.5
    Low

    CVE-2014-7980

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in template.php in Zen theme 7.x-3.x before 7.x-3.3 and 7.x-5.x before 7.x-5.5 for Drupal allow remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the skip_link_text setting and unspecified other theme settings.

    Published: 8 Oct 2014
    3.5
    Low

    CVE-2014-7978

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.

    Published: 8 Oct 2014
    9
    Critical

    CVE-2014-5308

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name parameter in a Search action to lib/project/projectView.php or (2) id parameter to lib/events/eventinfo.php.

    Published: 8 Oct 2014
    10
    Critical

    CVE-2014-7205

    Last Modified: 12 Apr 2025

    Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.

    Published: 8 Oct 2014
    6.8
    Medium

    CVE-2014-3187

    Last Modified: 12 Apr 2025

    Google Chrome before 37.0.2062.60 and 38.x before 38.0.2125.59 on iOS does not properly restrict processing of (1) facetime:// and (2) facetime-audio:// URLs, which allows remote attackers to obtain video and audio data from a device via a crafted web site.

    Published: 8 Oct 2014
    7.5
    High

    CVE-2014-3196

    Last Modified: 12 Apr 2025

    base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.

    Published: 8 Oct 2014
    6.8
    Medium

    CVE-2014-7273

    Last Modified: 12 Apr 2025

    The IMAP-over-SSL implementation in getmail 4.0.0 through 4.43.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate.

    Published: 8 Oct 2014
    5.8
    Medium

    CVE-2014-7274

    Last Modified: 12 Apr 2025

    The IMAP-over-SSL implementation in getmail 4.44.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IMAP servers and obtain sensitive information via a crafted certificate from a recognized Certification Authority.

    Published: 8 Oct 2014
    5.8
    Medium

    CVE-2014-7275

    Last Modified: 12 Apr 2025

    The POP3-over-SSL implementation in getmail 4.0.0 through 4.44.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof POP3 servers and obtain sensitive information via a crafted certificate.

    Published: 8 Oct 2014
    7.5
    High

    CVE-2014-7299

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in administrative interfaces in ArubaOS 6.3.1.11, 6.3.1.11-FIPS, 6.4.2.1, and 6.4.2.1-FIPS on Aruba controllers allows remote attackers to bypass authentication, and obtain potentially sensitive information or add guest accounts, via an SSH session.

    Published: 8 Oct 2014
    7.5
    High

    CVE-2014-7967

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before 38.0.2125.101, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 8 Oct 2014
    5.5
    Medium

    CVE-2014-7970

    Last Modified: 12 Apr 2025

    The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call.

    Published: 8 Oct 2014
    5.5
    Medium

    CVE-2014-7975

    Last Modified: 12 Apr 2025

    The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.

    Published: 8 Oct 2014
    10
    Critical

    CVE-2014-6433

    Last Modified: 12 Apr 2025

    gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action.

    Published: 7 Oct 2014
    9.3
    Critical

    CVE-2014-5501

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file.

    Published: 7 Oct 2014
    9
    Critical

    CVE-2014-5502

    Last Modified: 12 Apr 2025

    The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key, (2) webclient_portal_settings, (3) sslvpn_liveuser_delete, or (4) ccc_flush_sql_file opcode.

    Published: 7 Oct 2014
    10
    Critical

    CVE-2014-5503

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Guest Login Portal in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary SQL commands via the add_guest_user opcode.

    Published: 7 Oct 2014
    10
    Critical

    CVE-2014-6434

    Last Modified: 12 Apr 2025

    gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action.

    Published: 7 Oct 2014
    5
    Medium

    CVE-2014-6603

    Last Modified: 12 Apr 2025

    The SSHParseBanner function in SSH parser (app-layer-ssh.c) in Suricata before 2.0.4 allows remote attackers to bypass SSH rules, cause a denial of service (crash), or possibly have unspecified other impact via a crafted banner, which triggers a large memory allocation or an out-of-bounds write.

    Published: 7 Oct 2014
    4.3
    Medium

    CVE-2014-7189

    Last Modified: 12 Apr 2025

    crpyto/tls in Go 1.1 before 1.3.2, when SessionTicketsDisabled is enabled, allows man-in-the-middle attackers to spoof clients via unspecified vectors.

    Published: 7 Oct 2014
    10
    Critical

    CVE-2014-7235

    Last Modified: 12 Apr 2025

    htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP unserialize function, as exploited in the wild in September 2014.

    Published: 7 Oct 2014