CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-3070

    Last Modified: 12 Apr 2025

    The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3 does not properly create accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 22 Aug 2014
    3.5
    Low

    CVE-2014-5274

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the view operations page in phpMyAdmin 4.1.x before 4.1.14.3 and 4.2.x before 4.2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted view name, related to js/functions.js.

    Published: 22 Aug 2014
    4.9
    Medium

    CVE-2014-3089

    Last Modified: 12 Apr 2025

    The RDS Java Client library in IBM Rational Directory Server (RDS) 5.1.1.x before 5.1.1.2 iFix004 and 5.2.x before 5.2.1 iFix003, and Rational Directory Administrator (RDA) 6.0 before iFix002, includes the cleartext root password, which allows local users to obtain sensitive information by reading a library file.

    Published: 22 Aug 2014
    5
    Medium

    CVE-2014-3436

    Last Modified: 12 Apr 2025

    Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted encrypted e-mail message that decompresses to a larger size.

    Published: 22 Aug 2014
    7.1
    High

    CVE-2014-4764

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors.

    Published: 22 Aug 2014
    6.5
    Medium

    CVE-2014-4767

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.3 does not properly use the Liberty Repository for feature installation, which allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 22 Aug 2014
    6.8
    Medium

    CVE-2014-3604

    Last Modified: 12 Apr 2025

    Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 22 Aug 2014
    4.3
    Medium

    CVE-2009-5142

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb 1.09 and earlier, as used in Mimbo Pro 2.3.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the src parameter.

    Published: 21 Aug 2014
    4.3
    Medium

    CVE-2010-5302

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb before 1.15 as of 20100908 (r88), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.

    Published: 21 Aug 2014
    4.3
    Medium

    CVE-2010-5303

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorString.

    Published: 21 Aug 2014
    5
    Medium

    CVE-2014-5385

    Last Modified: 12 Apr 2025

    com/salesmanager/central/profile/ProfileAction.java in Shopizer 1.1.5 and earlier does not restrict the number of authentication attempts, which makes it easier for remote attackers to guess passwords via a brute force attack.

    Published: 21 Aug 2014
    5
    Medium

    CVE-2014-5384

    Last Modified: 12 Apr 2025

    The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out-of-bounds array access) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT from CVE-2014-3951 per ADT2 due to different vulnerability types.

    Published: 21 Aug 2014
    5
    Medium

    CVE-2014-3951

    Last Modified: 12 Apr 2025

    The HZ module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted argument to the iconv_open function. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2014-5384 is used for the NULL pointer dereference.

    Published: 21 Aug 2014
    10
    Critical

    CVE-2014-5210

    Last Modified: 12 Apr 2025

    The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.

    Published: 21 Aug 2014
    10
    Critical

    CVE-2014-5158

    Last Modified: 12 Apr 2025

    The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 21 Aug 2014
    7.5
    High

    CVE-2014-5159

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary SQL commands via the ws_data parameter.

    Published: 21 Aug 2014
    6.5
    Medium

    CVE-2014-5383

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Aug 2014
    9.3
    Critical

    CVE-2014-3524

    Last Modified: 12 Apr 2025

    Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.

    Published: 21 Aug 2014
    4.3
    Medium

    CVE-2014-3587

    Last Modified: 12 Apr 2025

    Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.

    Published: 21 Aug 2014
    6.9
    Medium

    CVE-2014-3182

    Last Modified: 12 Apr 2025

    Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.

    Published: 21 Aug 2014
    6.9
    Medium

    CVE-2014-3183

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that specifies a large report size for an LED report.

    Published: 21 Aug 2014
    4.7
    Medium

    CVE-2014-3184

    Last Modified: 12 Apr 2025

    The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.

    Published: 21 Aug 2014
    4.3
    Medium

    CVE-2014-3575

    Last Modified: 12 Apr 2025

    The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects.

    Published: 21 Aug 2014
    2.1
    Low

    CVE-2014-5351

    Last Modified: 12 Apr 2025

    The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold request, which allows remote authenticated users to forge tickets by leveraging administrative access.

    Published: 21 Aug 2014
    6.8
    Medium

    CVE-2014-4929

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the routing component in ownCloud Server before 5.0.17 and 6.0.x before 6.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in a filename, related to index.php.

    Published: 20 Aug 2014
    4.3
    Medium

    CVE-2014-5382

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Schrack Technik microControl with firmware 1.7.0 (937) allow remote attackers to inject arbitrary web script or HTML via the position textbox in the configuration menu or other unspecified vectors.

    Published: 20 Aug 2014
    5.4
    Medium

    CVE-2014-2505

    Last Modified: 12 Apr 2025

    EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to trigger the download of arbitrary code, and consequently change the product's functionality, via unspecified vectors.

    Published: 20 Aug 2014
    4.3
    Medium

    CVE-2014-4749

    Last Modified: 12 Apr 2025

    IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle attackers to spoof SSH servers via an arbitrary server key.

    Published: 20 Aug 2014
    2.9
    Low

    CVE-2014-4750

    Last Modified: 12 Apr 2025

    IBM PowerVC Express Edition 1.2.0 before FixPack3 establishes an FTP session for transferring files to a managed IVM, which allows remote attackers to discover credentials by sniffing the network.

    Published: 20 Aug 2014
    4.3
    Medium

    CVE-2014-3331

    Last Modified: 12 Apr 2025

    The Session Manager component in Packet Data Network Gateway (aka PGW) in Cisco ASR 5000 Series Software 11.0, 12.0, 12.1, 12.2, 14.0, 15.0, 16.x through 16.1.2, and 17.0 allows remote attackers to cause a denial of service (process crash) via a crafted TCP packet, aka Bug ID CSCuo21914.

    Published: 20 Aug 2014
    6.8
    Medium

    CVE-2014-0641

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 20 Aug 2014
    4.3
    Medium

    CVE-2014-2511

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.

    Published: 20 Aug 2014
    6.5
    Medium

    CVE-2014-2517

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 20 Aug 2014
    6.8
    Medium

    CVE-2014-2518

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Documentum WDK before 6.7SP1 P28 and 6.7SP2 before P15 allow remote attackers to hijack the authentication of arbitrary users.

    Published: 20 Aug 2014
    6.3
    Medium

    CVE-2014-2520

    Last Modified: 12 Apr 2025

    EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07, when Oracle Database is used, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and read sensitive database content via a crafted request.

    Published: 20 Aug 2014
    6.3
    Medium

    CVE-2014-2521

    Last Modified: 12 Apr 2025

    EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to read sensitive object metadata via an RPC command.

    Published: 20 Aug 2014
    4
    Medium

    CVE-2014-0640

    Last Modified: 12 Apr 2025

    EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to bypass intended restrictions on resource access via unspecified vectors.

    Published: 20 Aug 2014
    8.5
    High

    CVE-2014-2515

    Last Modified: 12 Apr 2025

    EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properly restrict tickets provided by D2GetAdminTicketMethod and D2RefreshCacheMethod, which allows remote authenticated users to gain privileges via a request for a superuser ticket.

    Published: 20 Aug 2014
    4
    Medium

    CVE-2014-3340

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in an unspecified PHP script in the server in Cisco WebEx MeetMeNow allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCuo16166.

    Published: 20 Aug 2014
    8.5
    High

    CVE-2014-4618

    Last Modified: 12 Apr 2025

    EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to gain privileges via a user-created system object.

    Published: 20 Aug 2014
    5.8
    Medium

    CVE-2014-0480

    Last Modified: 12 Apr 2025

    The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slash) in a URL, which triggers a scheme-relative URL to be generated.

    Published: 20 Aug 2014
    6
    Medium

    CVE-2014-0482

    Last Modified: 12 Apr 2025

    The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticated users to hijack web sessions via vectors related to the REMOTE_USER header.

    Published: 20 Aug 2014
    3.5
    Low

    CVE-2014-0483

    Last Modified: 12 Apr 2025

    The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated users to obtain sensitive information via a to_field parameter in a popup action to an admin change form page, as demonstrated by a /admin/auth/user/?pop=1&t=password URI.

    Published: 20 Aug 2014
    4.3
    Medium

    CVE-2014-0481

    Last Modified: 12 Apr 2025

    The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is uploaded, which allows remote attackers to cause a denial of service (CPU consumption) by unloading a multiple files with the same name.

    Published: 20 Aug 2014
    4
    Medium

    CVE-2014-8333

    Last Modified: 12 Apr 2025

    The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.

    Published: 20 Aug 2014
    4.3
    Medium

    CVE-2014-5348

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in apps/zxtm/locallog.cgi in Riverbed Stingray (aka SteelApp) Traffic Manager Virtual Appliance 9.6 patchlevel 9620140312 allows remote attackers to inject arbitrary web script or HTML via the logfile parameter.

    Published: 19 Aug 2014
    5
    Medium

    CVE-2014-5349

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print JavaScript function.

    Published: 19 Aug 2014
    4.3
    Medium

    CVE-2014-5345

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.

    Published: 19 Aug 2014
    6.8
    Medium

    CVE-2014-5346

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) activate or (2) deactivate the plugin via the active parameter to wp-admin/edit-comments.php, (3) import comments via an import_comments action, or (4) export comments via an export_comments action to wp-admin/index.php.

    Published: 19 Aug 2014
    6.8
    Medium

    CVE-2014-5347

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) disqus_replace, (2) disqus_public_key, or (3) disqus_secret_key parameter to wp-admin/edit-comments.php in manage.php or that (4) reset or (5) delete plugin options via the reset parameter to wp-admin/edit-comments.php.

    Published: 19 Aug 2014