CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2014-4377

    Last Modified: 12 Apr 2025

    Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

    Published: 18 Sept 2014
    5.8
    Medium

    CVE-2014-4378

    Last Modified: 12 Apr 2025

    CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted PDF document.

    Published: 18 Sept 2014
    7.1
    High

    CVE-2014-4379

    Last Modified: 12 Apr 2025

    An unspecified IOHIDFamily function in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking to prevent reading of kernel pointers, which allows attackers to bypass the ASLR protection mechanism via a crafted application.

    Published: 18 Sept 2014
    9.3
    Critical

    CVE-2014-4380

    Last Modified: 12 Apr 2025

    The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code in the kernel's context via a crafted application.

    Published: 18 Sept 2014
    9.3
    Critical

    CVE-2014-4389

    Last Modified: 12 Apr 2025

    Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted API arguments.

    Published: 18 Sept 2014
    6.9
    Medium

    CVE-2014-4408

    Last Modified: 12 Apr 2025

    The rt_setgate function in the kernel in Apple iOS before 8 and Apple TV before 7 allows local users to gain privileges or cause a denial of service (out-of-bounds read and device crash) via a crafted call.

    Published: 18 Sept 2014
    4.3
    Medium

    CVE-2014-4409

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 8 makes it easier for remote attackers to track users during private browsing via a crafted web site that reads HTML5 application-cache data that had been stored during normal browsing.

    Published: 18 Sept 2014
    6.8
    Medium

    CVE-2014-4410

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.

    Published: 18 Sept 2014
    6.8
    Medium

    CVE-2014-4414

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 8 and Apple TV before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-09-17-1 and APPLE-SA-2014-09-17-2.

    Published: 18 Sept 2014
    7.8
    High

    CVE-2014-4418

    Last Modified: 12 Apr 2025

    IOKit in Apple iOS before 8 and Apple TV before 7 does not properly validate IODataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via an application that provides crafted values in unspecified metadata fields, a different vulnerability than CVE-2014-4388.

    Published: 18 Sept 2014
    1.9
    Low

    CVE-2014-4419

    Last Modified: 12 Apr 2025

    The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4420, and CVE-2014-4421.

    Published: 18 Sept 2014
    1.9
    Low

    CVE-2014-4421

    Last Modified: 12 Apr 2025

    The network-statistics interface in the kernel in Apple iOS before 8 and Apple TV before 7 does not properly initialize memory, which allows attackers to obtain sensitive memory-content and memory-layout information via a crafted application, a different vulnerability than CVE-2014-4371, CVE-2014-4419, and CVE-2014-4420.

    Published: 18 Sept 2014
    8.1
    High

    CVE-2014-4422

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 8 and Apple TV before 7 uses a predictable random number generator during the early portion of the boot process, which allows attackers to bypass certain kernel-hardening protection mechanisms by using a user-space process to observe data related to the random numbers.

    Published: 18 Sept 2014
    4
    Medium

    CVE-2014-4819

    Last Modified: 12 Apr 2025

    The web user interface in IBM WebSphere Message Broker 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.3 allows remote authenticated users to obtain sensitive information by reading the error page.

    Published: 18 Sept 2014
    4.3
    Medium

    CVE-2014-4820

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Integration Bus Manufacturing Pack 1.x before 1.0.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Sept 2014
    6.5
    Medium

    CVE-2014-4824

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM Security QRadar SIEM 7.2 before 7.2.3 Patch 1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 18 Sept 2014
    4.3
    Medium

    CVE-2014-5317

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in php365.com 365 Links 3.11 and earlier, 365 Links2 3.11 and earlier, 365 Links+ 2.10 and earlier, and 365 Links2+ 2.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5921

    Last Modified: 12 Apr 2025

    The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5922

    Last Modified: 12 Apr 2025

    The ga6748 (aka com.g.ga6748) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5923

    Last Modified: 12 Apr 2025

    The Facebook Status Via (aka com.StatusViaAdvanced) application 3.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5924

    Last Modified: 12 Apr 2025

    The Monster Makeup (aka com.bearhugmedia.android_monster) application 1.0.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5925

    Last Modified: 12 Apr 2025

    The 10000 Kindle Books Downloads (aka com.ww10000KindleBooksLatestnBestSellers) application 0.312 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5926

    Last Modified: 12 Apr 2025

    The DCU Mobile Banking (aka com.Vertifi.Mobile.P211391825) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5929

    Last Modified: 12 Apr 2025

    The emartmall (aka kr.co.emart.emartmall) application 1.3.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5930

    Last Modified: 12 Apr 2025

    The Store and Share (aka sg.com.singnet.mystorage.android) application 2.0.18 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5931

    Last Modified: 12 Apr 2025

    The Stop & Shop SCAN IT! Mobile (aka com.modivmedia.scanitss) application 7.21.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5932

    Last Modified: 12 Apr 2025

    The Vodafone Mobile@Work (aka com.mobileiron.vodafone.MIClient) application 6.0.0.1.12R for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5935

    Last Modified: 12 Apr 2025

    The Daily Free App @ Amazon (aka com.kattanweb.android.dfaa) application 1.5.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5936

    Last Modified: 12 Apr 2025

    The INCOgnito Private Browser (aka com.SL.InCoBrowser) application 1.4.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5939

    Last Modified: 12 Apr 2025

    The travelzadcomvb (aka com.tapatalk.travelzadcomvb) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5940

    Last Modified: 12 Apr 2025

    The PocketPC.ch (aka com.tapatalk.pocketpcch) application 3.9.51 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5943

    Last Modified: 12 Apr 2025

    The LabMSF Antivirus beta (aka com.ReSync.RNGN) 1.0.2 application Beta for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5944

    Last Modified: 12 Apr 2025

    The Soccer Blitz (aka soccer.blitz) application 1.06 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5945

    Last Modified: 12 Apr 2025

    The Edline Mobile (aka com.wEdlineFree) application 0.63.13369.34294 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5946

    Last Modified: 12 Apr 2025

    The forumhawaaworldcom (aka com.tapatalk.forumhawaaworldcom) application 3.4.12 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5948

    Last Modified: 12 Apr 2025

    The Obama for America (aka com.barackobama.ofa) application 1.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5949

    Last Modified: 12 Apr 2025

    The TICKET APP - Concerts & Sports (aka com.xcr.android.ticketapp) application 3.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5950

    Last Modified: 12 Apr 2025

    The NOW (aka com.smtown.smtownnow.androidapp) application 0.9.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5951

    Last Modified: 12 Apr 2025

    The SinoPac (aka com.sionpac.app.SinoPac) application 2.4.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5952

    Last Modified: 12 Apr 2025

    The E-Dziennik (aka com.librus.dziennik) application 0.5.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5.4
    Medium

    CVE-2014-5953

    Last Modified: 12 Apr 2025

    The KASKUS (aka com.kaskus.android) application 2.13.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Sept 2014
    5
    Medium

    CVE-2014-3195

    Last Modified: 12 Apr 2025

    Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of double-precision floating-point numbers, which allows remote attackers to obtain sensitive information via crafted JavaScript code, related to the PagedSpace::AllocateRaw and NewSpace::AllocateRaw functions in heap/spaces-inl.h, the LargeObjectSpace::AllocateRaw function in heap/spaces.cc, and the Runtime_ArrayConcat function in runtime.cc.

    Published: 18 Sept 2014
    7.5
    High

    CVE-2014-3669

    Last Modified: 12 Apr 2025

    Integer overflow in the object_custom function in ext/standard/var_unserializer.c in PHP before 5.4.34, 5.5.x before 5.5.18, and 5.6.x before 5.6.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an argument to the unserialize function that triggers calculation of a large length value.

    Published: 18 Sept 2014
    2.1
    Low

    CVE-2014-4330

    Last Modified: 12 Apr 2025

    The Dumper method in Data::Dumper before 2.154, as used in Perl 5.20.1 and earlier, allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an Array-Reference with many nested Array-References, which triggers a large number of recursive calls to the DD_dump function.

    Published: 18 Sept 2014
    4.3
    Medium

    CVE-2012-6658

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName configuration in snmpd.conf. NOTE: this entry was SPLIT from CVE-2012-2956 per ADT2 due to different vulnerability types.

    Published: 17 Sept 2014
    6.5
    Medium

    CVE-2012-2956

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6658 is for the XSS.

    Published: 17 Sept 2014
    4.3
    Medium

    CVE-2014-5235

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via vectors related to unspecified fields in RSS feeds.

    Published: 17 Sept 2014
    4.3
    Medium

    CVE-2014-5234

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite before 7.4.2-rev33 and 7.6.x before 7.6.0-rev16 allows remote attackers to inject arbitrary web script or HTML via a folder publication name.

    Published: 17 Sept 2014
    4.3
    Medium

    CVE-2012-1032

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Sept 2014
    4.3
    Medium

    CVE-2012-1507

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to templates/hrfunct/emppop.php, or (3) uri parameter to index.php.

    Published: 17 Sept 2014