CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2014-2390

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the User Management module in McAfee Network Security Manager (NSM) before 6.1.15.39 7.1.5.x before 7.1.5.15, 7.1.15.x before 7.1.15.7, 7.5.x before 7.5.5.9, and 8.x before 8.1.7.3 allows remote attackers to hijack the authentication of users for requests that modify user accounts via unspecified vectors.

    Published: 29 Aug 2014
    5
    Medium

    CVE-2014-5337

    Last Modified: 12 Apr 2025

    The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attackers to obtain sensitive information via an exportarticles action to export/content.php.

    Published: 29 Aug 2014
    5
    Medium

    CVE-2014-5128

    Last Modified: 12 Apr 2025

    Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive information via unspecified vectors.

    Published: 29 Aug 2014
    5.8
    Medium

    CVE-2014-5127

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.

    Published: 29 Aug 2014
    4.3
    Medium

    CVE-2014-4930

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in event/index2.do in ManageEngine EventLog Analyzer before 9.0 build 9002 allow remote attackers to inject arbitrary web script or HTML via the (1) width, (2) height, (3) url, (4) helpP, (5) tab, (6) module, (7) completeData, (8) RBBNAME, (9) TC, (10) rtype, (11) eventCriteria, (12) q, (13) flushCache, or (14) product parameter. Fixed in Build 11072.

    Published: 29 Aug 2014
    9
    Critical

    CVE-2014-2593

    Last Modified: 12 Apr 2025

    The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacters in certain arguments of a valid command, as demonstrated by the (1) system status-rasession and (2) network ping commands.

    Published: 29 Aug 2014
    4.3
    Medium

    CVE-2012-1503

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

    Published: 29 Aug 2014
    5.5
    Medium

    CVE-2014-4806

    Last Modified: 12 Apr 2025

    The installation process in IBM Security AppScan Enterprise 8.x before 8.6.0.2 iFix 003, 8.7.x before 8.7.0.1 iFix 003, 8.8.x before 8.8.0.1 iFix 002, and 9.0.x before 9.0.0.1 iFix 001 on Linux places a cleartext password in a temporary file, which allows local users to obtain sensitive information by reading this file.

    Published: 29 Aug 2014
    5
    Medium

    CVE-2014-3351

    Last Modified: 12 Apr 2025

    Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, aka Bug IDs CSCuh87398 and CSCuh87380.

    Published: 29 Aug 2014
    4
    Medium

    CVE-2014-3350

    Last Modified: 12 Apr 2025

    Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly implement URL redirection, which allows remote authenticated users to obtain sensitive information via a crafted URL, aka Bug ID CSCuh84870.

    Published: 29 Aug 2014
    4
    Medium

    CVE-2014-3349

    Last Modified: 12 Apr 2025

    Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not validate file types during the handling of file submission, which allows remote authenticated users to upload arbitrary files via a crafted request, aka Bug ID CSCuh87410.

    Published: 29 Aug 2014
    6.3
    Medium

    CVE-2014-3346

    Last Modified: 12 Apr 2025

    The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) does not validate an unspecified parameter, which allows remote authenticated users to cause a denial of service (service crash) via a crafted string, aka Bug ID CSCuq31819.

    Published: 29 Aug 2014
    2.1
    Low

    CVE-2014-3093

    Last Modified: 12 Apr 2025

    IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the installation process, (4) environment checks, (5) powervc-ldap-config, (6) powervc-restore, and (7) powervc-diag, which allows local users to obtain sensitive information by entering a ps command or reading a file.

    Published: 29 Aug 2014
    4.9
    Medium

    CVE-2014-3084

    Last Modified: 12 Apr 2025

    IBM Maximo Asset Management 6.1 through 6.5, 7.1 through 7.1.1.13, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2.8, 7.1, and 7.2 for Tivoli IT Asset Management for IT and certain other products allow remote authenticated users to bypass intended write-access restrictions on calendar entries via unspecified vectors.

    Published: 29 Aug 2014
    6
    Medium

    CVE-2014-3024

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 through 7.5.0.6 and Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk allows remote authenticated users to hijack the authentication of arbitrary users.

    Published: 29 Aug 2014
    3.5
    Low

    CVE-2014-0897

    Last Modified: 12 Apr 2025

    The Configuration Patterns component in IBM Flex System Manager (FSM) 1.2.0.x, 1.2.1.x, 1.3.0.x, and 1.3.1.x uses a weak algorithm in an encryption step during Chassis Management Module (CMM) account creation, which makes it easier for remote authenticated users to defeat cryptographic protection mechanisms via unspecified vectors.

    Published: 29 Aug 2014
    4.9
    Medium

    CVE-2014-0888

    Last Modified: 12 Apr 2025

    IBM Worklight Foundation 5.x and 6.x before 6.2.0.0, as used in Worklight and Mobile Foundation, allows remote authenticated users to bypass the application-authenticity feature via unspecified vectors.

    Published: 29 Aug 2014
    7.8
    High

    CVE-2014-0600

    Last Modified: 12 Apr 2025

    FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via the poLibMaintenanceFileSave parameter, aka ZDI-CAN-2287.

    Published: 29 Aug 2014
    7.2
    High

    CVE-2013-5467

    Last Modified: 12 Apr 2025

    Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow local users to gain privileges via unspecified vectors.

    Published: 29 Aug 2014
    5
    Medium

    CVE-2014-3345

    Last Modified: 12 Apr 2025

    The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted URL, aka Bug ID CSCuq31503.

    Published: 28 Aug 2014
    5.4
    Medium

    CVE-2014-3347

    Last Modified: 12 Apr 2025

    Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid state of the hardware encryption module, aka Bug ID CSCul77897.

    Published: 28 Aug 2014
    7.5
    High

    CVE-2014-5399

    Last Modified: 1 Nov 2025

    SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Aug 2014
    7.5
    High

    CVE-2014-5397

    Last Modified: 1 Nov 2025

    Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Aug 2014
    7.8
    High

    CVE-2014-2380

    Last Modified: 1 Nov 2025

    Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file.

    Published: 28 Aug 2014
    2.1
    Low

    CVE-2014-5398

    Last Modified: 1 Nov 2025

    Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 28 Aug 2014
    2.1
    Low

    CVE-2014-2381

    Last Modified: 1 Nov 2025

    Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file.

    Published: 28 Aug 2014
    7.1
    High

    CVE-2014-0761

    Last Modified: 19 Sept 2025

    The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows remote attackers to cause a denial of service (infinite loop or process crash) via a crafted TCP packet.

    Published: 28 Aug 2014
    4.3
    Medium

    CVE-2014-3344

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuq31129, CSCuq31134, CSCuq31137, and CSCuq31563.

    Published: 28 Aug 2014
    9.3
    Critical

    CVE-2014-4619

    Last Modified: 12 Apr 2025

    EMC RSA Identity Management and Governance (IMG) 6.5.x before 6.5.1 P11, 6.5.2 before P02HF01, and 6.8.x before 6.8.1 P07, when Novell Identity Manager (aka NovellIM) is used, allows remote attackers to bypass authentication via an arbitrary valid username.

    Published: 28 Aug 2014
    4.7
    Medium

    CVE-2014-0762

    Last Modified: 19 Sept 2025

    The CG Automation Software DNP3 driver, used in the ePAQ-9410 Substation Gateway products, does not validate input correctly. An attacker could cause the software to go into an infinite loop, causing the process to crash. The system must be restarted manually to clear the condition.

    Published: 28 Aug 2014
    5
    Medium

    CVE-2014-6040

    Last Modified: 12 Apr 2025

    GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting (1) IBM933, (2) IBM935, (3) IBM937, (4) IBM939, or (5) IBM1364 encoded data to UTF-8.

    Published: 28 Aug 2014
    5
    Medium

    CVE-2014-3609

    Last Modified: 12 Apr 2025

    HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."

    Published: 28 Aug 2014
    7.5
    High

    CVE-2014-3171

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the V8 bindings in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper use of HashMap add operations instead of HashMap set operations, related to bindings/core/v8/DOMWrapperMap.h and bindings/core/v8/SerializedScriptValue.cpp.

    Published: 27 Aug 2014
    5
    Medium

    CVE-2014-3174

    Last Modified: 12 Apr 2025

    modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly consider concurrent threads during attempts to update biquad filter coefficients, which allows remote attackers to cause a denial of service (read of uninitialized memory) via crafted API calls.

    Published: 27 Aug 2014
    10
    Critical

    CVE-2014-3175

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors, related to the load_truetype_glyph function in truetype/ttgload.c in FreeType and other functions in other components.

    Published: 27 Aug 2014
    10
    Critical

    CVE-2014-3176

    Last Modified: 12 Apr 2025

    Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3177.

    Published: 27 Aug 2014
    10
    Critical

    CVE-2014-3177

    Last Modified: 12 Apr 2025

    Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3176.

    Published: 27 Aug 2014
    7.5
    High

    CVE-2014-3168

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper caching associated with animation.

    Published: 27 Aug 2014
    7.5
    High

    CVE-2014-3169

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging script execution that occurs before notification of node removal.

    Published: 27 Aug 2014
    6.4
    Medium

    CVE-2014-3170

    Last Modified: 12 Apr 2025

    extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote attackers to spoof the extension permission dialog by relying on truncation after this character.

    Published: 27 Aug 2014
    6.4
    Medium

    CVE-2014-3172

    Last Modified: 12 Apr 2025

    The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL before an attach operation, which allows remote attackers to bypass intended access limitations via an extension that uses a restricted URL, as demonstrated by a chrome:// URL.

    Published: 27 Aug 2014
    5
    Medium

    CVE-2014-3173

    Last Modified: 12 Apr 2025

    The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with the state of a draw buffer, which allows remote attackers to cause a denial of service (read of uninitialized memory) via a crafted CANVAS element, related to gpu/command_buffer/service/framebuffer_manager.cc and gpu/command_buffer/service/gles2_cmd_decoder.cc.

    Published: 27 Aug 2014
    6.9
    Medium

    CVE-2014-3186

    Last Modified: 12 Apr 2025

    Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.

    Published: 27 Aug 2014
    6.9
    Medium

    CVE-2014-3181

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with an event.

    Published: 27 Aug 2014
    7.2
    High

    CVE-2014-5307

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain privileges via a crafted argument to a 0x222008 IOCTL call.

    Published: 26 Aug 2014
    6.8
    Medium

    CVE-2014-3061

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 26 Aug 2014
    6.8
    Medium

    CVE-2014-3907

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.11 for WordPress allows remote attackers to hijack the authentication of arbitrary users.

    Published: 26 Aug 2014
    6.8
    Medium

    CVE-2014-2527

    Last Modified: 12 Apr 2025

    kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) character in the directory name, a different vulnerability than CVE-2014-2528.

    Published: 26 Aug 2014
    6.8
    Medium

    CVE-2014-2528

    Last Modified: 12 Apr 2025

    kcleanup.cpp in KDirStat 2.7.3 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a ' (single quote) character in the directory name, a different vulnerability than CVE-2014-2527.

    Published: 26 Aug 2014
    3.5
    Low

    CVE-2014-3034

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 26 Aug 2014