CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-5637

    Last Modified: 12 Apr 2025

    The Eu Sei (aka com.guilardi.eusei) application eusei_android_5.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5638

    Last Modified: 12 Apr 2025

    The Huntington Mobile (aka com.huntington.m) application 2.1.222 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5639

    Last Modified: 12 Apr 2025

    The ADT Taxis (aka com.icabbi.adttaxisApp) application 6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    5.4
    Medium

    CVE-2014-5640

    Last Modified: 12 Apr 2025

    The CM Backup -Restore,Cloud,Photo (aka com.ijinshan.kbackup) application 1.1.0.135 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0549

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0547, CVE-2014-0550, CVE-2014-0551, CVE-2014-0552, and CVE-2014-0555.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0554

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to bypass intended access restrictions via unspecified vectors.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0559

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0556.

    Published: 9 Sept 2014
    6.9
    Medium

    CVE-2014-0205

    Last Modified: 12 Apr 2025

    The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that triggers a zero count.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0547

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, CVE-2014-0552, and CVE-2014-0555.

    Published: 9 Sept 2014
    7.5
    High

    CVE-2014-0548

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0551

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0552, and CVE-2014-0555.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0552

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, and CVE-2014-0555.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0553

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0557

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 do not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0550

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0547, CVE-2014-0549, CVE-2014-0551, CVE-2014-0552, and CVE-2014-0555.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0555

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0547, CVE-2014-0549, CVE-2014-0550, CVE-2014-0551, and CVE-2014-0552.

    Published: 9 Sept 2014
    10
    Critical

    CVE-2014-0556

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before 15.0.0.249 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0559.

    Published: 9 Sept 2014
    7.2
    High

    CVE-2014-3631

    Last Modified: 12 Apr 2025

    The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation.

    Published: 9 Sept 2014
    6.4
    Medium

    CVE-2014-7141

    Last Modified: 12 Apr 2025

    The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

    Published: 9 Sept 2014
    7.8
    High

    CVE-2014-3535

    Last Modified: 12 Apr 2025

    include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectly uses macros for netdev_printk and its related logging implementation, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) by sending invalid packets to a VxLAN interface.

    Published: 9 Sept 2014
    4.9
    Medium

    CVE-2014-6268

    Last Modified: 12 Apr 2025

    The evtchn_fifo_set_pending function in Xen 4.4.x allows local guest users to cause a denial of service (host crash) via vectors involving an uninitialized FIFO-based event channel control block when (1) binding or (2) moving an event to a different VCPU.

    Published: 9 Sept 2014
    6.8
    Medium

    CVE-2014-6270

    Last Modified: 12 Apr 2025

    Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.

    Published: 9 Sept 2014
    4.3
    Medium

    CVE-2014-5369

    Last Modified: 12 Apr 2025

    Enigmail 1.7.x before 1.7.2 sends emails in plaintext when encryption is enabled and only BCC recipients are specified, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 8 Sept 2014
    4.3
    Medium

    CVE-2014-5464

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

    Published: 8 Sept 2014
    5
    Medium

    CVE-2014-3581

    Last Modified: 12 Apr 2025

    The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP Content-Type header.

    Published: 8 Sept 2014
    4.6
    Medium

    CVE-2015-3255

    Last Modified: 12 Apr 2025

    The polkit_backend_action_pool_init function in polkitbackend/polkitbackendactionpool.c in PolicyKit (aka polkit) before 0.113 might allow local users to gain privileges via duplicate action IDs in action descriptions.

    Published: 7 Sept 2014
    5
    Medium

    CVE-2014-6428

    Last Modified: 12 Apr 2025

    The dissect_spdu function in epan/dissectors/packet-ses.c in the SES dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 does not initialize a certain ID value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 7 Sept 2014
    4.3
    Medium

    CVE-2014-2379

    Last Modified: 13 Oct 2025

    Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to interfere with traffic control by replaying transmissions on a wireless network.

    Published: 5 Sept 2014
    6.5
    Medium

    CVE-2014-2378

    Last Modified: 13 Oct 2025

    Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not verify the integrity of downloaded updates, which allows remote attackers to execute arbitrary code via a Trojan horse update.

    Published: 5 Sept 2014
    6.8
    Medium

    CVE-2014-3909

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in Falcon WisePoint 4.1.19.7 and earlier allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 5 Sept 2014
    4.4
    Medium

    CVE-2014-3910

    Last Modified: 12 Apr 2025

    Emurasoft EmFTP allows local users to gain privileges via a Trojan horse executable file that is launched during an attempt to read a similarly named file that lacks a filename extension.

    Published: 5 Sept 2014
    5
    Medium

    CVE-2014-0877

    Last Modified: 12 Apr 2025

    IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page and then following a generated link.

    Published: 5 Sept 2014
    5
    Medium

    CVE-2014-4863

    Last Modified: 12 Apr 2025

    The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.

    Published: 5 Sept 2014
    5
    Medium

    CVE-2014-4862

    Last Modified: 12 Apr 2025

    The Netmaster CBW700N cable modem with software 81.447.392110.729.024 has an SNMP community of public, which allows remote attackers to obtain sensitive credential, key, and SSID information via an SNMP request.

    Published: 5 Sept 2014
    3.5
    Low

    CVE-2014-5508

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the HelpServ module (mod-helpserv.c) in srvx 1.3.1 allow remote authenticated IRCops or HelpServ bot managers to cause a denial of service (infinite loop) via a large value in the EmptyInterval parameter or certain other interval configurations.

    Published: 5 Sept 2014
    4.9
    Medium

    CVE-2014-6029

    Last Modified: 12 Apr 2025

    TorrentFlux 2.4 allows remote authenticated users to delete or modify other users' cookies via the cid parameter in an editCookies action to profile.php.

    Published: 5 Sept 2014
    4
    Medium

    CVE-2014-6028

    Last Modified: 12 Apr 2025

    TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.

    Published: 5 Sept 2014
    1.9
    Low

    CVE-2014-5036

    Last Modified: 12 Apr 2025

    The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.

    Published: 5 Sept 2014
    6.5
    Medium

    CVE-2014-6252

    Last Modified: 12 Apr 2025

    Buffer overflow in disp+work.exe 7000.52.12.34966 and 7200.117.19.50294 in the Dispatcher in SAP NetWeaver 7.00 and 7.20 allows remote authenticated users to cause a denial of service or execute arbitrary code via unspecified vectors.

    Published: 5 Sept 2014
    4
    Medium

    CVE-2014-0863

    Last Modified: 12 Apr 2025

    The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in memory, which allows remote authenticated users to obtain sensitive cleartext information via an unspecified security tool.

    Published: 5 Sept 2014
    10
    Critical

    CVE-2014-0610

    Last Modified: 12 Apr 2025

    The client in Novell GroupWise before 8.0.3 HP4, 2012 before SP3, and 2014 before SP1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference) via unspecified vectors.

    Published: 5 Sept 2014
    5.5
    Medium

    CVE-2013-0163

    Last Modified: 21 Nov 2024

    OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS

    Published: 5 Sept 2014
    6.5
    Medium

    CVE-2013-0196

    Last Modified: 21 Nov 2024

    A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.

    Published: 5 Sept 2014
    5
    Medium

    CVE-2014-3578

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

    Published: 5 Sept 2014
    2.1
    Low

    CVE-2014-3615

    Last Modified: 12 Apr 2025

    The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.

    Published: 5 Sept 2014
    3.3
    Low

    CVE-2014-6060

    Last Modified: 12 Apr 2025

    The get_option function in dhcpcd 4.0.0 through 6.x before 6.4.3 allows remote DHCP servers to cause a denial of service by resetting the DHO_OPTIONSOVERLOADED option in the (1) bootfile or (2) servername section, which triggers the option to be processed again.

    Published: 4 Sept 2014
    7.5
    High

    CVE-2014-2685

    Last Modified: 12 Apr 2025

    The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 violate the OpenID 2.0 protocol by ensuring only that at least one field is signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.

    Published: 4 Sept 2014
    5
    Medium

    CVE-2014-5269

    Last Modified: 12 Apr 2025

    Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a crafted path, related to Plack::Middleware::Static.

    Published: 4 Sept 2014
    5
    Medium

    CVE-2014-5377

    Last Modified: 12 Apr 2025

    ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.

    Published: 4 Sept 2014
    6.8
    Medium

    CVE-2014-5505

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in SAP Crystal Reports allows remote attackers to execute arbitrary code via a crafted data source string in an RPT file.

    Published: 4 Sept 2014