CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2014-5506

    Last Modified: 12 Apr 2025

    Double free vulnerability in SAP Crystal Reports allows remote attackers to execute arbitrary code via crafted connection string record in an RPT file.

    Published: 4 Sept 2014
    7.5
    High

    CVE-2014-5504

    Last Modified: 12 Apr 2025

    SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database and execute arbitrary code via unspecified vectors, related to HyperSQL.

    Published: 4 Sept 2014
    4.3
    Medium

    CVE-2012-4234

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the group moderation screen in the control center (control.php) in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via the group parameter.

    Published: 4 Sept 2014
    4.3
    Medium

    CVE-2012-4768

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.

    Published: 4 Sept 2014
    3.5
    Low

    CVE-2014-3075

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file.

    Published: 4 Sept 2014
    7.1
    High

    CVE-2014-3353

    Last Modified: 12 Apr 2025

    Cisco IOS XR 4.3(.2) and earlier, as used in Cisco Carrier Routing System (CRS), allows remote attackers to cause a denial of service (CPU consumption and IPv6 packet drops) via a malformed IPv6 packet, aka Bug ID CSCuo95165.

    Published: 4 Sept 2014
    8.5
    High

    CVE-2014-3094

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.

    Published: 4 Sept 2014
    3.5
    Low

    CVE-2014-3095

    Last Modified: 12 Apr 2025

    The SQL engine in IBM DB2 9.5 through FP10, 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted UNION clause in a subquery of a SELECT statement.

    Published: 4 Sept 2014
    4
    Medium

    CVE-2014-4758

    Last Modified: 12 Apr 2025

    IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.

    Published: 4 Sept 2014
    4
    Medium

    CVE-2014-4759

    Last Modified: 12 Apr 2025

    An unspecified Ajax service in the Content Management toolkit in IBM Business Process Manager (BPM) 8.5.x through 8.5.5 allows remote authenticated users to obtain sensitive information by performing a document-attachment search and then reading document properties in the search results.

    Published: 4 Sept 2014
    2.1
    Low

    CVE-2014-4805

    Last Modified: 12 Apr 2025

    IBM DB2 10.5 before FP4 on Linux and AIX creates temporary files during CDE table LOAD operations, which allows local users to obtain sensitive information by reading a file while a LOAD is occurring.

    Published: 4 Sept 2014
    7.5
    High

    CVE-2014-5285

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Authentication Module in TIBCO Spotfire Server before 4.5.2, 5.0.x before 5.0.3, 5.5.x before 5.5.2, 6.0.x before 6.0.3, and 6.5.x before 6.5.1 allows remote attackers to gain privileges, and obtain sensitive information or modify data, via unknown vectors.

    Published: 4 Sept 2014
    6.5
    Medium

    CVE-2014-3573

    Last Modified: 12 Apr 2025

    The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML/RSDL document, related to an XML External Entity (XXE) issue.

    Published: 4 Sept 2014
    4
    Medium

    CVE-2014-7960

    Last Modified: 12 Apr 2025

    OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.

    Published: 4 Sept 2014
    7.5
    High

    CVE-2014-3618

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted email header, related to "unbalanced quotes."

    Published: 4 Sept 2014
    5
    Medium

    CVE-2014-5465

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 3 Sept 2014
    4.3
    Medium

    CVE-2012-4226

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Quick Post Widget plugin 1.9.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Title, (2) Content, or (3) New category field to wordpress/ or (4) query string to wordpress/.

    Published: 3 Sept 2014
    4.3
    Medium

    CVE-2014-1566

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1515.

    Published: 3 Sept 2014
    9.3
    Critical

    CVE-2014-1567

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.

    Published: 3 Sept 2014
    7.5
    High

    CVE-2015-2675

    Last Modified: 20 Apr 2025

    The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.

    Published: 3 Sept 2014
    10
    Critical

    CVE-2014-1563

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG animation with DOM interaction that triggers incorrect cycle collection.

    Published: 3 Sept 2014
    10
    Critical

    CVE-2014-1554

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 3 Sept 2014
    4.3
    Medium

    CVE-2014-1564

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script that interacts with a CANVAS element associated with a malformed GIF image.

    Published: 3 Sept 2014
    5
    Medium

    CVE-2014-1565

    Last Modified: 12 Apr 2025

    The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 does not properly create audio timelines, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted API calls.

    Published: 3 Sept 2014
    10
    Critical

    CVE-2014-1553

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 3 Sept 2014
    10
    Critical

    CVE-2014-1562

    Last Modified: 25 Nov 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 3 Sept 2014
    4
    Medium

    CVE-2014-6064

    Last Modified: 12 Apr 2025

    The Accounts tab in the administrative user interface in McAfee Web Gateway (MWG) before 7.3.2.9 and 7.4.x before 7.4.2 allows remote authenticated users to obtain the hashed user passwords via unspecified vectors.

    Published: 2 Sept 2014
    7.5
    High

    CVE-2014-0485

    Last Modified: 12 Apr 2025

    S3QL 1.18.1 and earlier uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object in (1) common.py or (2) local.py in backends/.

    Published: 2 Sept 2014
    4.3
    Medium

    CVE-2014-5136

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Innovative Interfaces Sierra Library Services Platform 1.2_3 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 2 Sept 2014
    5
    Medium

    CVE-2014-5137

    Last Modified: 12 Apr 2025

    Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of login requests, possibly related to the Webpac Pro submodule.

    Published: 2 Sept 2014
    6.5
    Medium

    CVE-2014-5521

    Last Modified: 12 Apr 2025

    plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.

    Published: 2 Sept 2014
    5.8
    Medium

    CVE-2014-6041

    Last Modified: 12 Apr 2025

    The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 character, as demonstrated by an onclick="window.open('\u0000javascript: sequence to the Android Browser application 4.2.1 or a third-party web browser.

    Published: 2 Sept 2014
    4.3
    Medium

    CVE-2014-3861

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted reference element within a nonXMLBody element.

    Published: 2 Sept 2014
    4.3
    Medium

    CVE-2014-3862

    Last Modified: 12 Apr 2025

    CDA.xsl in HL7 C-CDA 1.1 and earlier allows remote attackers to discover potentially sensitive URLs via a crafted reference element that triggers creation of an IMG element with an arbitrary URL in its SRC attribute, leading to information disclosure in a Referer log.

    Published: 2 Sept 2014
    4.3
    Medium

    CVE-2014-5076

    Last Modified: 12 Apr 2025

    The La Banque Postale application before 3.2.6 for Android does not prevent the launching of an activity by a component of another application, which allows attackers to obtain sensitive cached banking information via crafted intents, as demonstrated by the drozer framework.

    Published: 2 Sept 2014
    4.3
    Medium

    CVE-2014-5452

    Last Modified: 12 Apr 2025

    CDA.xsl in HL7 C-CDA 1.1 and earlier does not anticipate the possibility of invalid C-CDA documents with crafted XML attributes, which allows remote attackers to conduct XSS attacks via a document containing a table that is improperly handled during unrestricted xsl:copy operations.

    Published: 2 Sept 2014
    6.1
    Medium

    CVE-2014-6071

    Last Modified: 21 Nov 2024

    jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside after.

    Published: 2 Sept 2014
    5
    Medium

    CVE-2014-3598

    Last Modified: 12 Apr 2025

    The Jpeg2KImagePlugin plugin in Pillow before 2.5.3 allows remote attackers to cause a denial of service via a crafted image.

    Published: 1 Sept 2014
    Unknown

    CVE-2014-6033

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6032. Reason: This candidate is a duplicate of CVE-2014-6032. Notes: All CVE users should reference CVE-2014-6032 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 1 Sept 2014
    8.4
    High

    CVE-2013-2597

    Last Modified: 22 Apr 2026

    Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.

    Published: 31 Aug 2014
    3.3
    Low

    CVE-2013-6124

    Last Modified: 12 Apr 2025

    The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x allow local users to modify file metadata via a symlink attack on a file accessed by a (1) chown or (2) chmod command, as demonstrated by changing the permissions of an arbitrary file via an attack on the sensor-settings file.

    Published: 31 Aug 2014
    6.6
    Medium

    CVE-2013-2598

    Last Modified: 12 Apr 2025

    app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to overwrite signature-verification code via crafted boot-image load-destination header values that specify memory locations within bootloader memory.

    Published: 31 Aug 2014
    7.2
    High

    CVE-2013-2595

    Last Modified: 12 Apr 2025

    The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which allows attackers to gain privileges via a crafted application.

    Published: 31 Aug 2014
    5
    Medium

    CVE-2013-2599

    Last Modified: 12 Apr 2025

    A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server/NativeDaemonConnector.java in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.3.x enables debug logging, which allows attackers to obtain sensitive disk-encryption passwords via a logcat call.

    Published: 31 Aug 2014
    5
    Medium

    CVE-2014-3565

    Last Modified: 12 Apr 2025

    snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB file, as demonstrated by a NULL type in an ifMtu trap message.

    Published: 31 Aug 2014
    5.8
    Medium

    CVE-2014-3908

    Last Modified: 12 Apr 2025

    The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 30 Aug 2014
    4.3
    Medium

    CVE-2014-3352

    Last Modified: 12 Apr 2025

    Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh84801.

    Published: 30 Aug 2014
    2.1
    Low

    CVE-2014-5247

    Last Modified: 12 Apr 2025

    The _UpgradeBeforeConfigurationChange function in lib/client/gnt_cluster.py in Ganeti 2.10.0 before 2.10.7 and 2.11.0 before 2.11.5 uses world-readable permissions for the configuration backup file, which allows local users to obtain SSL keys, remote API credentials, and other sensitive information by reading the file, related to the upgrade command.

    Published: 29 Aug 2014
    4.3
    Medium

    CVE-2014-5147

    Last Modified: 12 Apr 2025

    Xen 4.4.x, when running a 64-bit kernel on an ARM system, does not properly handle traps from the guest domain that use a different address width, which allows local guest users to cause a denial of service (host crash) via a crafted 32-bit process.

    Published: 29 Aug 2014
    7.5
    High

    CVE-2014-5073

    Last Modified: 12 Apr 2025

    vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call.

    Published: 29 Aug 2014