CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2014-7295

    Last Modified: 12 Apr 2025

    The (1) Special:Preferences and (2) Special:UserLogin pages in MediaWiki before 1.19.20, 1.22.x before 1.22.12 and 1.23.x before 1.23.5 allows remote authenticated users to conduct cross-site scripting (XSS) attacks or have unspecified other impact via crafted CSS, as demonstrated by modifying MediaWiki:Common.css.

    Published: 7 Oct 2014
    9.8
    Critical

    CVE-2014-6287

    Last Modified: 22 Apr 2026

    The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.

    Published: 7 Oct 2014
    4
    Medium

    CVE-2014-4802

    Last Modified: 12 Apr 2025

    The Saved Search Admin component in the Process Admin Console in IBM Business Process Manager (BPM) 8.0 through 8.5.5 does not properly restrict task and instance listings in result sets, which allows remote authenticated users to bypass authorization checks and obtain sensitive information by executing a saved search.

    Published: 7 Oct 2014
    5.5
    Medium

    CVE-2014-3399

    Last Modified: 12 Apr 2025

    The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cache files or inject Lua programs, and consequently cause a denial of service (portal outage or system reload), via crafted HTTP requests, aka Bug ID CSCup54208.

    Published: 7 Oct 2014
    7.2
    High

    CVE-2014-4870

    Last Modified: 12 Apr 2025

    /opt/vyatta/bin/sudo-users/vyatta-clear-dhcp-lease.pl on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 does not properly validate parameters, which allows local users to gain privileges by leveraging the sudo configuration.

    Published: 7 Oct 2014
    5
    Medium

    CVE-2014-4869

    Last Modified: 12 Apr 2025

    The Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows attackers to obtain sensitive encrypted-password information by leveraging membership in the operator group.

    Published: 7 Oct 2014
    4.3
    Medium

    CVE-2014-0940

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Service Automation Manager 7.2.2.2 before 7.2.2.2-TIV-TSAM-LA0041 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) REST API or (2) Self Service UI.

    Published: 7 Oct 2014
    9
    Critical

    CVE-2014-4868

    Last Modified: 12 Apr 2025

    The management console on the Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows remote authenticated users to execute arbitrary Linux commands via shell metacharacters in a console command.

    Published: 7 Oct 2014
    4.3
    Medium

    CVE-2014-4871

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in wlsecurity.html on NetCommWireless NB604N routers with firmware before GAN5.CZ56T-B-NC.AU-R4B030.EN allows remote attackers to inject arbitrary web script or HTML via the wlWpaPsk parameter.

    Published: 7 Oct 2014
    5
    Medium

    CVE-2014-3198

    Last Modified: 12 Apr 2025

    The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 7 Oct 2014
    7.5
    High

    CVE-2014-3190

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that accesses the path property of an Event object.

    Published: 7 Oct 2014
    7.5
    High

    CVE-2014-3192

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 7 Oct 2014
    7.5
    High

    CVE-2014-3193

    Last Modified: 12 Apr 2025

    The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that leverage "type confusion" for callback processing.

    Published: 7 Oct 2014
    5
    Medium

    CVE-2014-3197

    Last Modified: 12 Apr 2025

    The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site.

    Published: 7 Oct 2014
    5
    Medium

    CVE-2014-3199

    Last Modified: 12 Apr 2025

    The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an erroneous fallback outcome for wrapper-selection failures, which allows remote attackers to cause a denial of service via vectors that trigger stopping a worker process that had been handling an Event object.

    Published: 7 Oct 2014
    7.5
    High

    CVE-2014-3189

    Last Modified: 12 Apr 2025

    The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via unknown vectors.

    Published: 7 Oct 2014
    7.5
    High

    CVE-2014-3191

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers a widget-position update that improperly interacts with the render tree, related to the FrameView::updateLayoutAndStyleForPainting function in core/frame/FrameView.cpp and the RenderLayerScrollableArea::setScrollOffset function in core/rendering/RenderLayerScrollableArea.cpp.

    Published: 7 Oct 2014
    7.5
    High

    CVE-2014-3194

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 7 Oct 2014
    7.5
    High

    CVE-2014-3200

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 7 Oct 2014
    6.1
    Medium

    CVE-2014-9717

    Last Modified: 12 Apr 2025

    fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneath a mount by calling umount2 within a user namespace.

    Published: 7 Oct 2014
    7.5
    High

    CVE-2014-2044

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbitrary names, and execute arbitrary code via an Alternate Data Stream (ADS) syntax in the filename parameter, as demonstrated using .htaccess::$DATA to upload a PHP program.

    Published: 6 Oct 2014
    7.5
    High

    CVE-2013-1436

    Last Modified: 12 Apr 2025

    The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the xmobar window title, as demonstrated using an action tag.

    Published: 6 Oct 2014
    5
    Medium

    CVE-2013-7329

    Last Modified: 12 Apr 2025

    The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive information (web queries and environment details) via vectors related to the dump_html function.

    Published: 6 Oct 2014
    10
    Critical

    CVE-2014-0397

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in libXtsol in Oracle Solaris 10 and 11.1 have unspecified impact and attack vectors related to "Buffer errors."

    Published: 6 Oct 2014
    4.3
    Medium

    CVE-2014-1224

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in the user registration feature in rexx Recruitment R6.1 and R7 without "fixes from 2014-01-15" allows remote attackers to conduct cross-site scripting (XSS) attacks via the oninput event handler in the fname parameter to the default URI in /reg.

    Published: 6 Oct 2014
    7.5
    High

    CVE-2014-6607

    Last Modified: 12 Apr 2025

    M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via the fullname and password parameters, a different vulnerability than CVE-2014-6409.

    Published: 6 Oct 2014
    4.3
    Medium

    CVE-2014-4510

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in job.cc in apt-cacher-ng 0.7.26 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 6 Oct 2014
    7.5
    High

    CVE-2014-6389

    Last Modified: 12 Apr 2025

    backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter.

    Published: 6 Oct 2014
    6.8
    Medium

    CVE-2014-6409

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that change user passwords via the fullname and password parameters to /admin/users/update.

    Published: 6 Oct 2014
    6.8
    Medium

    CVE-2014-0994

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the ReadDIB function in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows context-dependent attackers to execute arbitrary code via the BITMAPINFOHEADER.biClrUsed field in a BMP file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0993.

    Published: 6 Oct 2014
    7.5
    High

    CVE-2014-5389

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in content-audit-schedule.php in the Content Audit plugin before 1.6.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the "Audited content types" option in the content-audit page to wp-admin/options-general.php.

    Published: 6 Oct 2014
    3.5
    Low

    CVE-2014-7869

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the configuration UI in the Context Form Alteration module 7.x-1.x before 7.x-1.2 for Drupal allows remote authenticated users with the "administer contexts" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Oct 2014
    3.5
    Low

    CVE-2014-7870

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with the "administer custom search" permission to inject arbitrary web script or HTML via the "Label text" field to admin/config/search/custom_search/results.

    Published: 6 Oct 2014
    4.3
    Medium

    CVE-2014-2644

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 6 Oct 2014
    9.3
    Critical

    CVE-2013-2645

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers to hijack the authentication of administrators for requests that (1) enable FTP access (aka "FTP directory traversal") to /tmp via the shareEntire parameter to userRpm/NasFtpCfgRpm.htm, (2) change the FTP administrative password via the nas_admin_pwd parameter to userRpm/NasUserAdvRpm.htm, (3) enable FTP on the WAN interface via the internetA parameter to userRpm/NasFtpCfgRpm.htm, (4) launch the FTP service via the startFtp parameter to userRpm/NasFtpCfgRpm.htm, or (5) enable or disable bandwidth limits via the QoSCtrl parameter to userRpm/QoSCfgRpm.htm.

    Published: 6 Oct 2014
    9.8
    Critical

    CVE-2014-10071

    Last Modified: 21 Nov 2024

    In exec.c in zsh before 5.0.7, there is a buffer overflow for very long fds in the ">& fd" syntax.

    Published: 6 Oct 2014
    7.5
    High

    CVE-2014-3691

    Last Modified: 12 Apr 2025

    Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.

    Published: 6 Oct 2014
    9.3
    Critical

    CVE-2014-7861

    Last Modified: 12 Apr 2025

    The IOHIDSecurePromptClient function in Apple OS X does not properly validate pointer values, which allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a crafted web site.

    Published: 5 Oct 2014
    4.3
    Medium

    CVE-2014-2645

    Last Modified: 12 Apr 2025

    HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to conduct clickjacking attacks via unknown vectors.

    Published: 5 Oct 2014
    Unknown

    CVE-2013-2644

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2645, CVE-2014-2644. Reason: this ID was intended for one issue, but was mapped to two issues. Notes: All CVE users should consult CVE-2013-2645 and CVE-2014-2644 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Oct 2014
    6.5
    Medium

    CVE-2014-2643

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 5 Oct 2014
    4
    Medium

    CVE-2014-3400

    Last Modified: 12 Apr 2025

    Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive information by reading logs, aka Bug IDs CSCuq36417 and CSCuq40344.

    Published: 5 Oct 2014
    7.5
    High

    CVE-2014-3396

    Last Modified: 12 Apr 2025

    Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass intended Typhoon line-card ACL restrictions via transit traffic, aka Bug ID CSCup30133.

    Published: 5 Oct 2014
    5
    Medium

    CVE-2014-3398

    Last Modified: 12 Apr 2025

    The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-version information by reading the verbose response data that is provided for a request to an unspecified URL, aka Bug ID CSCuq65542.

    Published: 5 Oct 2014
    5.4
    Medium

    CVE-2014-6906

    Last Modified: 12 Apr 2025

    The Loli Chocolate Cake (aka com.alison.kang.chocolatecake) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6914

    Last Modified: 12 Apr 2025

    The Houcine El Jasmi (aka com.devkhr31.houcineeljasmi) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6922

    Last Modified: 12 Apr 2025

    The KFAI Community Radio (aka com.skyblue.pra.kfai) application 2.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6930

    Last Modified: 12 Apr 2025

    The Abram Radio Groove! (aka com.nobexinc.wls_79226887.rc) application 3.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6907

    Last Modified: 12 Apr 2025

    The Rakuten Install (aka co.jp.rakuten.installapp) application 1.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014
    5.4
    Medium

    CVE-2014-6917

    Last Modified: 12 Apr 2025

    The www.knote.kr Smart (aka kr.or.knote.android) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 4 Oct 2014