CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2014-3035

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 26 Aug 2014
    6.5
    Medium

    CVE-2014-3041

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 26 Aug 2014
    6.8
    Medium

    CVE-2014-5035

    Last Modified: 12 Apr 2025

    The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference in an XML-RPC message, related to an XML External Entity (XXE) issue.

    Published: 26 Aug 2014
    4.3
    Medium

    CVE-2014-5336

    Last Modified: 12 Apr 2025

    Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allows remote attackers to cause a denial of service (file descriptor consumption) via an HTTP request that triggers an error message.

    Published: 26 Aug 2014
    3.3
    Low

    CVE-2013-6335

    Last Modified: 12 Apr 2025

    The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x before 6.3.2, 6.4.x before 6.4.2, and 7.1.x before 7.1.0.3 on Linux and AIX, and 5.x and 6.x before 6.1.5.6 on Solaris and HP-UX, does not preserve file permissions across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.

    Published: 26 Aug 2014
    6
    Medium

    CVE-2014-3040

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix 10, 10.0.0.x before 10.0.0.1 iFix 10, 10.0.1.x before 10.0.1.4, and 10.0.2.x before 10.0.2.2 iFix 2; Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4; and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 26 Aug 2014
    4.9
    Medium

    CVE-2014-4790

    Last Modified: 12 Apr 2025

    IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 do not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue.

    Published: 26 Aug 2014
    4.6
    Medium

    CVE-2014-3335

    Last Modified: 12 Apr 2025

    Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of packets with multicast destination MAC addresses, which allows remote attackers to cause a denial of service (chip and card hangs) via a crafted packet, aka Bug ID CSCup77750.

    Published: 26 Aug 2014
    3.5
    Low

    CVE-2014-3033

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 26 Aug 2014
    6.3
    Medium

    CVE-2014-4199

    Last Modified: 12 Apr 2025

    vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.

    Published: 26 Aug 2014
    4
    Medium

    CVE-2014-5471

    Last Modified: 12 Apr 2025

    Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.

    Published: 26 Aug 2014
    4.7
    Medium

    CVE-2014-4200

    Last Modified: 12 Apr 2025

    vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.

    Published: 26 Aug 2014
    4
    Medium

    CVE-2014-5472

    Last Modified: 12 Apr 2025

    The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.

    Published: 26 Aug 2014
    5.3
    Medium

    CVE-2014-5455

    Last Modified: 28 May 2026

    Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

    Published: 25 Aug 2014
    2.1
    Low

    CVE-2014-5457

    Last Modified: 12 Apr 2025

    QNAP TS-469U with firmware 4.0.7 Build 20140410, TS-459U, TS-EC1679U-RP, and SS-839 use world-readable permissions for /etc/config/shadow, which allows local users to obtain usernames and hashed passwords by reading the password.

    Published: 25 Aug 2014
    7.5
    High

    CVE-2014-5458

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in sqrl_verify.php in php-sqrl allows remote attackers to execute arbitrary SQL commands via the message parameter.

    Published: 25 Aug 2014
    6.8
    Medium

    CVE-2014-5335

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authentication of administrators for requests that modify configurations or user accounts, as demonstrated by (1) changing the administrator password via a crafted request to CMD0/mod_cmd.xml or (2) adding a new SIP user via a crafted request to PBX0/ADMIN/mod_cmd_login.xml.

    Published: 25 Aug 2014
    7.2
    High

    CVE-2014-5453

    Last Modified: 12 Apr 2025

    Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory (%PROGRAMFILES%\Ubisoft Game Launcher), which allows local users to gain privileges via a Trojan horse file.

    Published: 25 Aug 2014
    6
    Medium

    CVE-2014-5454

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

    Published: 25 Aug 2014
    2.1
    Low

    CVE-2014-5456

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Social Stats module before 7.x-1.5 for Drupal allows remote authenticated users with the "[Content Type]: Create new content" permission to inject arbitrary web script or HTML via vectors related to the configuration.

    Published: 25 Aug 2014
    7.5
    High

    CVE-2014-2216

    Last Modified: 12 Apr 2025

    The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted request.

    Published: 25 Aug 2014
    7.2
    High

    CVE-2014-0973

    Last Modified: 12 Apr 2025

    The image_verify function in platform/msm_shared/image_verify.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not check whether a certain digest size is consistent with the RSA_public_decrypt API specification, which makes it easier for attackers to bypass boot-image authentication requirements via trailing data.

    Published: 25 Aug 2014
    1.9
    Low

    CVE-2014-0974

    Last Modified: 12 Apr 2025

    The boot_linux_from_mmc function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly validate a certain address value, which allows attackers to write data to a controllable memory location by leveraging the ability to initiate an attempted boot of an arbitrary image.

    Published: 25 Aug 2014
    7.2
    High

    CVE-2014-4325

    Last Modified: 12 Apr 2025

    The cmd_boot function in app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to bypass intended device-lock and kernel-signature restrictions by using fastboot mode in a boot command for an arbitrary kernel image.

    Published: 25 Aug 2014
    5.3
    Medium

    CVE-2014-5209

    Last Modified: 21 Nov 2024

    An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information.

    Published: 25 Aug 2014
    3.6
    Low

    CVE-2014-5459

    Last Modified: 12 Apr 2025

    The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache functions.

    Published: 25 Aug 2014
    6.9
    Medium

    CVE-2014-3185

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in the command_port_read_callback function in drivers/usb/serial/whiteheat.c in the Whiteheat USB Serial Driver in the Linux kernel before 3.16.2 allow physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with a bulk response.

    Published: 24 Aug 2014
    4.3
    Medium

    CVE-2013-6222

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Mobility Web Client and Service Request Catalog (SRC) components in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Aug 2014
    10
    Critical

    CVE-2014-2632

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the WebTier component in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 23 Aug 2014
    6.8
    Medium

    CVE-2014-2633

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 23 Aug 2014
    9.4
    Critical

    CVE-2014-2634

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the server in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to bypass intended access restrictions, and modify data or cause a denial of service, via unknown vectors.

    Published: 23 Aug 2014
    4.6
    Medium

    CVE-2013-6306

    Last Modified: 12 Apr 2025

    Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

    Published: 22 Aug 2014
    6.8
    Medium

    CVE-2014-5241

    Last Modified: 12 Apr 2025

    The JSONP endpoint in includes/api/ApiFormatJson.php in MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with a restricted character set.

    Published: 22 Aug 2014
    4.3
    Medium

    CVE-2014-5243

    Last Modified: 12 Apr 2025

    MediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism for transcluded pages, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

    Published: 22 Aug 2014
    4.3
    Medium

    CVE-2014-5242

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in mediawiki.page.image.pagination.js in MediaWiki 1.22.x before 1.22.9 and 1.23.x before 1.23.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving the multipageimagenavbox class in conjunction with an action=raw value.

    Published: 22 Aug 2014
    7.5
    High

    CVE-2014-4197

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Bank Soft Systems (BSS) RBS BS-Client 3.17.9 allow remote attackers to execute arbitrary SQL commands via the (1) CARDS or (2) XACTION parameter.

    Published: 22 Aug 2014
    10
    Critical

    CVE-2014-3525

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

    Published: 22 Aug 2014
    7.5
    High

    CVE-2014-5261

    Last Modified: 12 Apr 2025

    The graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a font size, related to the rrdtool commandline in lib/rrd.php.

    Published: 22 Aug 2014
    7.5
    High

    CVE-2014-5262

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the graph settings script (graph_settings.php) in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 22 Aug 2014
    4.3
    Medium

    CVE-2014-0232

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1) result or (2) error message.

    Published: 22 Aug 2014
    5.8
    Medium

    CVE-2014-5122

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, related to login.

    Published: 22 Aug 2014
    10
    Critical

    CVE-2014-5246

    Last Modified: 12 Apr 2025

    The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.

    Published: 22 Aug 2014
    7.5
    High

    CVE-2014-5097

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php.

    Published: 22 Aug 2014
    4.3
    Medium

    CVE-2014-5121

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 22 Aug 2014
    5
    Medium

    CVE-2014-5368

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control (wp-source-control) plugin 3.0.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter.

    Published: 22 Aug 2014
    7.5
    High

    CVE-2014-5396

    Last Modified: 12 Apr 2025

    The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for the "user" account, which makes it easier for remote attackers to obtain access via unspecified vectors.

    Published: 22 Aug 2014
    4.3
    Medium

    CVE-2014-0965

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted SOAP response.

    Published: 22 Aug 2014
    3.5
    Low

    CVE-2014-5273

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.2, 4.1.x before 4.1.14.3, and 4.2.x before 4.2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) browse table page, related to js/sql.js; (2) ENUM editor page, related to js/functions.js; (3) monitor page, related to js/server_status_monitor.js; (4) query charts page, related to js/tbl_chart.js; or (5) table relations page, related to libraries/tbl_relation.lib.php.

    Published: 22 Aug 2014
    5
    Medium

    CVE-2014-3083

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource access, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 22 Aug 2014
    4.3
    Medium

    CVE-2014-3022

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.3 allows remote attackers to obtain sensitive information via a crafted URL that triggers an error condition.

    Published: 22 Aug 2014