CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2012-1417

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.

    Published: 17 Sept 2014
    4.3
    Medium

    CVE-2012-2583

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.

    Published: 17 Sept 2014
    6.5
    Medium

    CVE-2012-1506

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from third party information.

    Published: 17 Sept 2014
    10
    Critical

    CVE-2014-0566

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0565.

    Published: 17 Sept 2014
    10
    Critical

    CVE-2014-0568

    Last Modified: 12 Apr 2025

    The NtSetInformationFile system call hook feature in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows allows attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context, via an NTFS junction attack.

    Published: 17 Sept 2014
    8.5
    High

    CVE-2014-4621

    Last Modified: 12 Apr 2025

    EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected system types, which allows remote authenticated users to obtain super-user privileges for system-object creation, and bypass intended restrictions on data access and server actions, via unspecified vectors.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5911

    Last Modified: 12 Apr 2025

    The Free App Icons & Icon Packs (aka com.jellytap.cooliconfinder) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    10
    Critical

    CVE-2014-0560

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.

    Published: 17 Sept 2014
    4.3
    Medium

    CVE-2014-0562

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."

    Published: 17 Sept 2014
    7.8
    High

    CVE-2014-0563

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors.

    Published: 17 Sept 2014
    10
    Critical

    CVE-2014-0565

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0566.

    Published: 17 Sept 2014
    10
    Critical

    CVE-2014-0561

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0567.

    Published: 17 Sept 2014
    10
    Critical

    CVE-2014-0567

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0561.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5912

    Last Modified: 12 Apr 2025

    The InNote (aka com.intsig.notes) application 1.0.3.20131119 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5914

    Last Modified: 12 Apr 2025

    The Finansbank Cep Subesi (aka com.finansbank.mobile.cepsube) application 1.1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    7.1
    High

    CVE-2014-4622

    Last Modified: 12 Apr 2025

    EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subgroups of privileged groups, which allows remote authenticated sysadmins to gain super-user privileges, and bypass intended restrictions on data access and server actions, via unspecified vectors.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5906

    Last Modified: 12 Apr 2025

    The Lil Wayne Slots: FREE SLOTS (aka com.lilwayneslots.slots.android) application 1.138 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5907

    Last Modified: 12 Apr 2025

    The Pet Salon (aka com.libiitech.petsalon) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5908

    Last Modified: 12 Apr 2025

    The Kmart (aka com.kmart.android) application @7F0C00EF for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5909

    Last Modified: 12 Apr 2025

    The watcha (aka com.frograms.watcha) application 2.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5910

    Last Modified: 12 Apr 2025

    The Dog Whistle (aka com.dogwhistle.dogtrainingandroidapp) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5913

    Last Modified: 12 Apr 2025

    The Allies in War (aka com.gamelion.aiw) application 1.3.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5915

    Last Modified: 12 Apr 2025

    The Tigo Copa Mundial FIFA 2014 (aka com.fwc2014.millicom.and) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5916

    Last Modified: 12 Apr 2025

    The Minha Oi (aka br.com.mobicare.minhaoi) application 1.15.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5917

    Last Modified: 12 Apr 2025

    The Slideshow 365 (aka com.Slideshow) application 3.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    5.4
    Medium

    CVE-2014-5918

    Last Modified: 12 Apr 2025

    The Secret Circle - talk freely (aka com.easyxapp.secret) application 2.2.00.26 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 17 Sept 2014
    3.3
    Low

    CVE-2013-1945

    Last Modified: 21 Nov 2024

    ruby193 uses an insecure LD_LIBRARY_PATH setting.

    Published: 17 Sept 2014
    4.3
    Medium

    CVE-2014-3653

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the template preview function in Foreman before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted provisioning template.

    Published: 17 Sept 2014
    5.8
    Medium

    CVE-2014-3633

    Last Modified: 12 Apr 2025

    The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via a crafted blkiotune query, which triggers an out-of-bounds read.

    Published: 17 Sept 2014
    7.5
    High

    CVE-2014-7143

    Last Modified: 25 Nov 2024

    Python Twisted 14.0 trustRoot is not respected in HTTP client

    Published: 17 Sept 2014
    2.1
    Low

    CVE-2014-3640

    Last Modified: 12 Apr 2025

    The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized socket.

    Published: 17 Sept 2014
    5
    Medium

    CVE-2013-6496

    Last Modified: 12 Apr 2025

    Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4) portal_skins/custom, or (5) logs Luci extension.

    Published: 16 Sept 2014
    4
    Medium

    CVE-2014-3621

    Last Modified: 12 Apr 2025

    The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.

    Published: 16 Sept 2014
    1.9
    Low

    CVE-2014-3636

    Last Modified: 12 Apr 2025

    D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors for a single sendmsg call.

    Published: 16 Sept 2014
    4.4
    Medium

    CVE-2014-3635

    Last Modified: 12 Apr 2025

    Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than the limit, which triggers a heap-based buffer overflow or an assertion failure.

    Published: 16 Sept 2014
    2.1
    Low

    CVE-2014-3637

    Last Modified: 12 Apr 2025

    D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descriptor.

    Published: 16 Sept 2014
    6.4
    Medium

    CVE-2014-7142

    Last Modified: 12 Apr 2025

    The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

    Published: 16 Sept 2014
    5.5
    Medium

    CVE-2014-3521

    Last Modified: 12 Apr 2025

    The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access restrictions via a crafted URL.

    Published: 16 Sept 2014
    2.1
    Low

    CVE-2014-3638

    Last Modified: 12 Apr 2025

    The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls.

    Published: 16 Sept 2014
    2.1
    Low

    CVE-2014-3639

    Last Modified: 12 Apr 2025

    The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connections) via a large number of incomplete connections.

    Published: 16 Sept 2014
    5
    Medium

    CVE-2014-2377

    Last Modified: 13 Oct 2025

    Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.

    Published: 15 Sept 2014
    7.5
    High

    CVE-2014-2376

    Last Modified: 13 Oct 2025

    SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Sept 2014
    8.3
    High

    CVE-2014-2375

    Last Modified: 13 Oct 2025

    Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5905

    Last Modified: 12 Apr 2025

    The Grocery List - Tomatoes (aka com.meucarrinho) application 5.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    3.5
    Low

    CVE-2014-4763

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Content Navigator in Content Engine in IBM FileNet Content Manager 5.2.x before 5.2.0.3-P8CPE-IF003 and Content Foundation 5.2.x before 5.2.0.3-P8CPE-IF003 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 15 Sept 2014
    5.4
    Medium

    CVE-2014-5895

    Last Modified: 12 Apr 2025

    The ShopYourWay (aka com.sears.shopyourway) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Sept 2014
    4.3
    Medium

    CVE-2014-6392

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Facebook app 14.0 and the Facebook Messenger app 10.0 for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted filename extension that is improperly handled during MIME sniffing of chat traffic. NOTE: the vendor disputes the significance of this report, because the user must accept an interstitial warning before the HTML file content is rendered, and because the HTML content's origin is a sandbox domain

    Published: 15 Sept 2014
    2.1
    Low

    CVE-2014-3077

    Last Modified: 12 Apr 2025

    IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

    Published: 15 Sept 2014
    6.8
    Medium

    CVE-2014-0993

    Last Modified: 12 Apr 2025

    Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows remote attackers to execute arbitrary code via a crafted BMP file.

    Published: 15 Sept 2014
    4
    Medium

    CVE-2014-3617

    Last Modified: 12 Apr 2025

    The forum_print_latest_discussions function in mod/forum/lib.php in Moodle through 2.4.11, 2.5.x before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2 allows remote authenticated users to bypass the individual answer-posting requirement without the mod/forum:viewqandawithoutposting capability, and discover an author's username, by leveraging the student role and visiting a Q&A forum.

    Published: 15 Sept 2014