CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2014-5393

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote authenticated users with the info permission to read arbitrary files in the webroot via unspecified vectors.

    Published: 11 Sept 2014
    4.3
    Medium

    CVE-2014-5129

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Avolve Software ProjectDox 8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Sept 2014
    6.5
    Medium

    CVE-2014-5460

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.

    Published: 11 Sept 2014
    4.3
    Medium

    CVE-2014-5391

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the JobScheduler Operations Center (JOC) in SOS JobScheduler before 1.6.4246 and 1.7.x before 1.7.4241 allows remote attackers to inject arbitrary web script or HTML via the hash property (location.hash).

    Published: 11 Sept 2014
    6.5
    Medium

    CVE-2014-6043

    Last Modified: 12 Apr 2025

    ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed in Build 10000.

    Published: 11 Sept 2014
    4.3
    Medium

    CVE-2014-6070

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index.php or (2) detail.php.

    Published: 11 Sept 2014
    7.5
    High

    CVE-2014-6231

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the CWT Frontend Edit (cwt_feedit) extension before 1.2.5 for TYPO3 allows remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 11 Sept 2014
    4
    Medium

    CVE-2014-6232

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the LDAP (eu_ldap) extension before 2.8.18 for TYPO3 allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 11 Sept 2014
    7.5
    High

    CVE-2014-6233

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Flat Manager (flatmgr) extension before 2.7.10 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 11 Sept 2014
    4.3
    Medium

    CVE-2014-6234

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Open Graph protocol (jh_opengraphprotocol) extension before 1.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Sept 2014
    4.3
    Medium

    CVE-2011-4887

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Violations Table in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall (WAF) 9.0 allows remote attackers to inject arbitrary web script or HTML via the username field.

    Published: 11 Sept 2014
    4.3
    Medium

    CVE-2012-0984

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) to_userid parameter to modules/pm/pmlite.php or the (2) current_file, (3) imgcat_id, or (4) target parameter to class/xoopseditor/tinymce/tinymce/jscripts/tiny_mce/plugins/xoopsimagemanager/xoopsimagebrowser.php.

    Published: 11 Sept 2014
    7.5
    High

    CVE-2014-2223

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file and a non-zero length PNG file, then accessing the PHP file via a direct request to it in plog-content/uploads/archive/.

    Published: 11 Sept 2014
    7.5
    High

    CVE-2014-5519

    Last Modified: 12 Apr 2025

    The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party information.

    Published: 11 Sept 2014
    7.5
    High

    CVE-2014-6235

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 11 Sept 2014
    7.5
    High

    CVE-2014-6236

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the LumoNet PHP Include (lumophpinclude) extension before 1.2.1 for TYPO3 allows remote attackers to execute arbitrary scripts via vectors related to extension links.

    Published: 11 Sept 2014
    3.5
    Low

    CVE-2014-6237

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the News Pack extension 0.1.0 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Sept 2014
    4.3
    Medium

    CVE-2014-6238

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Akronymmanager (aka SB Folderdownload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Sept 2014
    7.5
    High

    CVE-2014-6239

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Address visualization with Google Maps (st_address_map) extension before 0.3.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 11 Sept 2014
    4.3
    Medium

    CVE-2014-6240

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Google Sitemap (weeaar_googlesitemap) extension 0.4.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Sept 2014
    7.5
    High

    CVE-2014-6241

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the wt_directory extension before 1.4.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 11 Sept 2014
    6.5
    Medium

    CVE-2012-4240

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5871

    Last Modified: 12 Apr 2025

    The Piwik Mobile 2 (aka org.piwik.mobile2) application 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5870

    Last Modified: 12 Apr 2025

    The Kmart (aka com.kmart.android) application 6.2.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5863

    Last Modified: 12 Apr 2025

    The mpang.gp (aka air.com.cjenm.mpang.gp) application 4.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5864

    Last Modified: 12 Apr 2025

    The Swish payments (aka se.bankgirot.swish) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5865

    Last Modified: 12 Apr 2025

    The Ask.com (aka com.ask.android) application 2.2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5866

    Last Modified: 12 Apr 2025

    The CA DMV (aka gov.ca.dmv) application 2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5867

    Last Modified: 12 Apr 2025

    The Capital One Spark Pay (aka com.capitalone.sparkpay) application 0.9.81 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5868

    Last Modified: 12 Apr 2025

    The Cisco Technical Support (aka com.cisco.swtg_android) application 3.7.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5869

    Last Modified: 12 Apr 2025

    The CNNMoney Portfolio (aka com.cnn.cnnmoney) application 1.03 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5872

    Last Modified: 12 Apr 2025

    The SafeNetMobile Pass (aka securecomputing.devices.android.controller) application 8.3.7.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5873

    Last Modified: 12 Apr 2025

    The Sears (aka com.sears.android) application 6.2.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5874

    Last Modified: 12 Apr 2025

    The SplashID (aka com.splashidandroid) application 7.2.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5875

    Last Modified: 12 Apr 2025

    The Sylphone (aka com.sylpheo.prospectosyl) application 5.3.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5876

    Last Modified: 12 Apr 2025

    The WD My Cloud (aka com.wdc.wd2go) application 4.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5877

    Last Modified: 12 Apr 2025

    The TV Guide (aka net.micene.minigroup.palimpsests.lite) application 5.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    5.4
    Medium

    CVE-2014-5878

    Last Modified: 12 Apr 2025

    The ium (aka net.ium.mobile.android) application 3.3.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 11 Sept 2014
    10
    Critical

    CVE-2014-2624

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2264.

    Published: 11 Sept 2014
    6.8
    Medium

    CVE-2014-4865

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 10 Sept 2014
    5.4
    Medium

    CVE-2014-0351

    Last Modified: 12 Apr 2025

    The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere with communications by modifying the client-server data stream.

    Published: 10 Sept 2014
    Unknown

    CVE-2014-0352

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2216. Reason: This candidate is a reservation duplicate of CVE-2014-2216. Notes: All CVE users should reference CVE-2014-2216 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Sept 2014
    5
    Medium

    CVE-2014-0909

    Last Modified: 12 Apr 2025

    The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 10 Sept 2014
    6
    Medium

    CVE-2014-4785

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 10 Sept 2014
    5.4
    Medium

    CVE-2014-5862

    Last Modified: 12 Apr 2025

    The ecalendar2 (aka cn.etouch.ecalendar2) application 4.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 10 Sept 2014
    4
    Medium

    CVE-2014-6074

    Last Modified: 12 Apr 2025

    IBM UrbanCode Deploy 6.1.0.2 before IF1 allows remote authenticated users to read keystore secret keys via a direct request to a UI page.

    Published: 10 Sept 2014
    3.3
    Low

    CVE-2014-4864

    Last Modified: 12 Apr 2025

    The NETGEAR ProSafe Plus Configuration Utility creates configuration backup files containing cleartext passwords, which might allow remote attackers to obtain sensitive information by reading a file.

    Published: 10 Sept 2014
    7.5
    High

    CVE-2014-3178

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in core/dom/Node.cpp in Blink, as used in Google Chrome before 37.0.2062.120, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of render-tree inconsistencies.

    Published: 10 Sept 2014
    7.5
    High

    CVE-2014-3179

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.120 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 10 Sept 2014
    2.1
    Low

    CVE-2014-3079

    Last Modified: 12 Apr 2025

    The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to bypass authorization checks and visit unspecified URLs with license-usage data via a DESCRIBE clause in a SPARQL query.

    Published: 10 Sept 2014