CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-3662

    Last Modified: 12 Apr 2025

    Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.

    Published: 2 Oct 2014
    7.5
    High

    CVE-2014-3666

    Last Modified: 12 Apr 2025

    Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.

    Published: 2 Oct 2014
    5
    Medium

    CVE-2014-3683

    Last Modified: 12 Apr 2025

    Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash) via a large priority (PRI) value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3634.

    Published: 2 Oct 2014
    4.9
    Medium

    CVE-2014-7283

    Last Modified: 12 Apr 2025

    The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.

    Published: 2 Oct 2014
    10
    Critical

    CVE-2014-3059

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Administrative Console on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network.

    Published: 2 Oct 2014
    10
    Critical

    CVE-2014-3060

    Last Modified: 12 Apr 2025

    Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.5 allows remote attackers to obtain administrative privileges by leveraging access to an eXtreme Scale distributed ObjectGrid network and capturing a session cookie.

    Published: 2 Oct 2014
    4.3
    Medium

    CVE-2014-3097

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0-TIV-TFIM-IF0015, 6.2.1 before 6.2.1-TIV-TFIM-IF0007, and 6.2.2 before 6.2.2-TIV-TFIM-IF0011 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 2 Oct 2014
    2.7
    Low

    CVE-2014-3608

    Last Modified: 12 Apr 2025

    The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.

    Published: 2 Oct 2014
    5
    Medium

    CVE-2014-3661

    Last Modified: 12 Apr 2025

    Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.

    Published: 2 Oct 2014
    6.5
    Medium

    CVE-2014-3642

    Last Modified: 12 Apr 2025

    vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated users to gain privileges via unspecified vectors, related to an "insecure send method."

    Published: 2 Oct 2014
    4
    Medium

    CVE-2014-3667

    Last Modified: 12 Apr 2025

    Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.

    Published: 2 Oct 2014
    4.3
    Medium

    CVE-2014-3678

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Oct 2014
    5
    Medium

    CVE-2014-3679

    Last Modified: 12 Apr 2025

    The Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to obtain sensitive information by accessing unspecified pages.

    Published: 2 Oct 2014
    4
    Medium

    CVE-2014-3680

    Last Modified: 12 Apr 2025

    Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.

    Published: 2 Oct 2014
    4.3
    Medium

    CVE-2014-3681

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Oct 2014
    6.5
    Medium

    CVE-2014-4793

    Last Modified: 12 Apr 2025

    IBM WebSphere MQ 8.x before 8.0.0.1 does not properly enforce CHLAUTH rules for blocking client connections in certain circumstances related to the CONNAUTH attribute, which allows remote authenticated users to bypass intended queue-manager access restrictions via unspecified vectors.

    Published: 2 Oct 2014
    5
    Medium

    CVE-2014-7968

    Last Modified: 12 Apr 2025

    VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.

    Published: 2 Oct 2014
    4.3
    Medium

    CVE-2011-4624

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in facebook.php in the GRAND FlAGallery plugin (flash-album-gallery) before 1.57 for WordPress allows remote attackers to inject arbitrary web script or HTML via the i parameter.

    Published: 1 Oct 2014
    6.5
    Medium

    CVE-2012-0811

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Postfix Admin (aka postfixadmin) before 2.3.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the pw parameter to the pacrypt function, when mysql_encrypt is configured, or (2) unspecified vectors that are used in backup files generated by backup.php.

    Published: 1 Oct 2014
    7.5
    High

    CVE-2003-1598

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in log.header.php in WordPress 0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the posts variable.

    Published: 1 Oct 2014
    5.4
    Medium

    CVE-2014-6851

    Last Modified: 12 Apr 2025

    The New Beginnings CFC (aka com.goodbarber.nbcfc) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 1 Oct 2014
    5.4
    Medium

    CVE-2014-6852

    Last Modified: 12 Apr 2025

    The LedLine.gr Official (aka com.automon.ledline.gr) application 1.4.0.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 1 Oct 2014
    5.4
    Medium

    CVE-2014-6853

    Last Modified: 12 Apr 2025

    The Foxit MobilePDF - PDF Reader (aka com.foxit.mobile.pdf.lite) application 2.2.0.0616 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 1 Oct 2014
    5.4
    Medium

    CVE-2014-6854

    Last Modified: 12 Apr 2025

    The EyeXam (aka com.globaleyeventures.eyexam) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 1 Oct 2014
    5.4
    Medium

    CVE-2014-6855

    Last Modified: 12 Apr 2025

    The Long (aka com.imop.longjiang.android) application 1.0.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 1 Oct 2014
    5
    Medium

    CVE-2014-3657

    Last Modified: 12 Apr 2025

    The virDomainListPopulate function in conf/domain_conf.c in libvirt before 1.2.9 does not clean up the lock on the list of domains, which allows remote attackers to cause a denial of service (deadlock) via a NULL value in the second parameter in the virConnectListAllDomains API command.

    Published: 1 Oct 2014
    4.3
    Medium

    CVE-2014-6439

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Oct 2014
    6.4
    Medium

    CVE-2014-7284

    Last Modified: 12 Apr 2025

    The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values.

    Published: 1 Oct 2014
    8.3
    High

    CVE-2014-7188

    Last Modified: 12 Apr 2025

    The hvm_msr_read_intercept function in arch/x86/hvm/hvm.c in Xen 4.1 through 4.4.x uses an improper MSR range for x2APIC emulation, which allows local HVM guests to cause a denial of service (host crash) or read data from the hypervisor or other guests via unspecified vectors.

    Published: 1 Oct 2014
    5
    Medium

    CVE-2014-3395

    Last Modified: 12 Apr 2025

    Cisco WebEx Meetings Server (WMS) 2.5 allows remote attackers to trigger the download of arbitrary files via a crafted URL, aka Bug ID CSCup10343.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6838

    Last Modified: 12 Apr 2025

    The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6840

    Last Modified: 12 Apr 2025

    The My Wedding Planner (aka app.wedding) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6848

    Last Modified: 12 Apr 2025

    The DS file (aka com.synology.DSfile) application 4.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6839

    Last Modified: 12 Apr 2025

    The Alma Corinthiana (aka com.alma.corinthiana) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6841

    Last Modified: 12 Apr 2025

    The RTI INDIA (aka com.vbulletin.build_890) application 3.8.21 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    Unknown

    CVE-2014-6809

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6846, CVE-2014-6847. Reason: this ID was intended for one issue, but was assigned to two issues by a CNA. Notes: All CVE users should consult CVE-2014-6846 and CVE-2014-6847 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6837

    Last Modified: 12 Apr 2025

    The Hillside (aka com.hillside.hermanus) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6842

    Last Modified: 12 Apr 2025

    The Daily Advertiser Print (aka com.lafayettedailyadv.android.prod) application 6.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6843

    Last Modified: 12 Apr 2025

    The Sweatshop (aka com.orderingapps.sweatshop) application 2.96 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6844

    Last Modified: 12 Apr 2025

    The ABC Song (aka com.tabtale.abcsingalong) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6845

    Last Modified: 12 Apr 2025

    The MediaFire (aka com.mediafire.android) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6846

    Last Modified: 12 Apr 2025

    The Four Seasons Beverly Hills (aka com.intelitycorp.FourSeasons.android.ice) application @7F050007 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6847

    Last Modified: 12 Apr 2025

    The Horoscopes and Dreams (aka com.horoscopesanddreams) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    5.4
    Medium

    CVE-2014-6850

    Last Modified: 12 Apr 2025

    The SED Account (aka com.starkville.smartapps) application 1.153.0034 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Sept 2014
    4.3
    Medium

    CVE-2014-4727

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or HTML via the hostname in a DHCP request.

    Published: 30 Sept 2014
    5
    Medium

    CVE-2014-4728

    Last Modified: 12 Apr 2025

    The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request.

    Published: 30 Sept 2014
    4.3
    Medium

    CVE-2014-6619

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in register-exec.php in Restaurant Script (PizzaInn_Project) 1.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) fname, (2) lname, or (3) login parameter.

    Published: 30 Sept 2014
    4.3
    Medium

    CVE-2014-6618

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Your Online Shop allows remote attackers to inject arbitrary web script or HTML via the products_id parameter.

    Published: 30 Sept 2014
    6.8
    Medium

    CVE-2014-7190

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown or (2) reboot the server via a request to admin/system_shutdown.html.

    Published: 30 Sept 2014
    6.8
    Medium

    CVE-2014-5267

    Last Modified: 12 Apr 2025

    modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declaration in an XRDS document.

    Published: 30 Sept 2014