CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-5350

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter to webservice/CORE/downloadFullKitEpc/a/1 in the Web Console or (2) %2E%2E (encoded dot dot) in the default URI to port 7074 on the Update Server.

    Published: 19 Aug 2014
    4
    Medium

    CVE-2014-3504

    Last Modified: 12 Apr 2025

    The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

    Published: 19 Aug 2014
    4.3
    Medium

    CVE-2014-5343

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.

    Published: 19 Aug 2014
    4.3
    Medium

    CVE-2014-5344

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Mobiloud (mobiloud-mobile-app-plugin) plugin before 2.3.8 for WordPress allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 19 Aug 2014
    5
    Medium

    CVE-2014-3341

    Last Modified: 12 Apr 2025

    The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests depending on whether the VLAN ID exists, which allows remote attackers to enumerate VLANs via a series of requests, aka Bug ID CSCup85616.

    Published: 19 Aug 2014
    3.5
    Low

    CVE-2014-3903

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Cakifo theme 1.x before 1.6.2 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via crafted Exif data.

    Published: 19 Aug 2014
    7.5
    High

    CVE-2014-3906

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in OSK Advance-Flow 4.41 and earlier and Advance-Flow Forms 4.41 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Aug 2014
    5.8
    Medium

    CVE-2014-3596

    Last Modified: 12 Apr 2025

    The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.

    Published: 19 Aug 2014
    3.5
    Low

    CVE-2014-3594

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.

    Published: 19 Aug 2014
    4.3
    Medium

    CVE-2014-3601

    Last Modified: 12 Apr 2025

    The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large gfn value or (2) cause a denial of service (host OS memory consumption) by triggering a small gfn value that leads to permanently pinned pages.

    Published: 19 Aug 2014
    2.1
    Low

    CVE-2014-3602

    Last Modified: 12 Apr 2025

    Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number information for remote systems by reading /proc/net/tcp.

    Published: 19 Aug 2014
    4.6
    Medium

    CVE-2014-5388

    Last Modified: 12 Apr 2025

    Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corruption.

    Published: 19 Aug 2014
    7.5
    High

    CVE-2014-6438

    Last Modified: 20 Apr 2025

    The URI.decode_www_form_component method in Ruby before 1.9.2-p330 allows remote attackers to cause a denial of service (catastrophic regular expression backtracking, resource consumption, or application crash) via a crafted string.

    Published: 19 Aug 2014
    6.8
    Medium

    CVE-2014-5204

    Last Modified: 12 Apr 2025

    wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

    Published: 18 Aug 2014
    6.1
    Medium

    CVE-2014-2388

    Last Modified: 12 Apr 2025

    The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.

    Published: 18 Aug 2014
    4.9
    Medium

    CVE-2014-1469

    Last Modified: 12 Apr 2025

    BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file.

    Published: 18 Aug 2014
    Unknown

    CVE-2014-1470

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2388. Reason: This candidate is a reservation duplicate of CVE-2014-2388. Notes: All CVE users should reference CVE-2014-2388 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Aug 2014
    6.8
    Medium

    CVE-2014-5205

    Last Modified: 12 Apr 2025

    wp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force attack.

    Published: 18 Aug 2014
    5
    Medium

    CVE-2014-5265

    Last Modified: 12 Apr 2025

    The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 18 Aug 2014
    Unknown

    CVE-2014-3799

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue within the scope of CVE. Notes: none

    Published: 18 Aug 2014
    Unknown

    CVE-2014-5043

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Aug 2014
    7.5
    High

    CVE-2014-5203

    Last Modified: 12 Apr 2025

    wp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to execute arbitrary code via crafted serialized data.

    Published: 18 Aug 2014
    2.1
    Low

    CVE-2014-5240

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.

    Published: 18 Aug 2014
    5
    Medium

    CVE-2014-5266

    Last Modified: 12 Apr 2025

    The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption) via a large document, a different vulnerability than CVE-2014-5265.

    Published: 18 Aug 2014
    4.3
    Medium

    CVE-2014-3574

    Last Modified: 12 Apr 2025

    Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

    Published: 18 Aug 2014
    5.8
    Medium

    CVE-2014-3577

    Last Modified: 12 Apr 2025

    org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "CN=" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the "foo,CN=www.apache.org" string in the O field.

    Published: 18 Aug 2014
    7.5
    High

    CVE-2014-3514

    Last Modified: 12 Apr 2025

    activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote attackers to bypass the strong parameters protection mechanism via crafted input to an application that makes create_with calls.

    Published: 18 Aug 2014
    4.3
    Medium

    CVE-2014-3529

    Last Modified: 12 Apr 2025

    The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 18 Aug 2014
    9.3
    Critical

    CVE-2014-0327

    Last Modified: 12 Apr 2025

    The Terminal Upgrade Tool in the Pilot Below Deck Equipment (BDE) and OpenPort implementations on Iridium satellite terminals allows remote attackers to execute arbitrary code by uploading new firmware to TCP port 54321.

    Published: 17 Aug 2014
    7.5
    High

    CVE-2014-3063

    Last Modified: 12 Apr 2025

    IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 allow local users to obtain administrator privileges via unspecified vectors.

    Published: 17 Aug 2014
    5
    Medium

    CVE-2014-4775

    Last Modified: 12 Apr 2025

    IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1-FP15 and 10.x and 11.x before 11.3-IF2 do not properly protect credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 17 Aug 2014
    7.1
    High

    CVE-2014-5074

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition) via crafted TCP packets.

    Published: 17 Aug 2014
    4.3
    Medium

    CVE-2014-3080

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the key parameter to avctalert.php.

    Published: 17 Aug 2014
    6.3
    Medium

    CVE-2014-3081

    Last Modified: 12 Apr 2025

    prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbitrary files via the filename parameter.

    Published: 17 Aug 2014
    9.3
    Critical

    CVE-2014-0326

    Last Modified: 12 Apr 2025

    The Pilot Below Deck Equipment (BDE) and OpenPort implementations on Iridium satellite terminals allow remote attackers to read hardcoded credentials via the web interface.

    Published: 17 Aug 2014
    2.9
    Low

    CVE-2014-0905

    Last Modified: 12 Apr 2025

    IBM InfoSphere BigInsights 2.0 through 2.1.2 does not set the secure flag for the LTPA cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 17 Aug 2014
    6.8
    Medium

    CVE-2014-0969

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to hijack the authentication of arbitrary users.

    Published: 17 Aug 2014
    2.1
    Low

    CVE-2014-0876

    Last Modified: 12 Apr 2025

    Buffer overflow in the Java GUI Configuration Wizard and Preferences Editor in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.x and 6.x before 6.2.5.2, 6.3.x before 6.3.2, and 6.4.x before 6.4.2 on Windows and OS X allows local users to cause a denial of service (application crash or hang) via unspecified vectors.

    Published: 17 Aug 2014
    6.5
    Medium

    CVE-2014-0966

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.x and 11.x before 11.0-FP5 and InfoSphere Master Data Management Server for Product Information Management 9.x through 11.x before 11.3-IF2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Aug 2014
    7.1
    High

    CVE-2014-3085

    Last Modified: 12 Apr 2025

    systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the lpres parameter.

    Published: 17 Aug 2014
    4
    Medium

    CVE-2014-3087

    Last Modified: 12 Apr 2025

    callService.do in IBM Business Process Manager (BPM) 7.5 through 8.5.5 and WebSphere Lombardi Edition 7.2 through 7.2.0.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 17 Aug 2014
    10
    Critical

    CVE-2014-0609

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has unknown impact and attack vectors.

    Published: 17 Aug 2014
    4.3
    Medium

    CVE-2014-3905

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in tenfourzero Shutter 0.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Aug 2014
    4.3
    Medium

    CVE-2014-3900

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/picture_modify.php in the photo-edit subsystem in Piwigo 2.6.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the associate[] field, a different vulnerability than CVE-2014-4649.

    Published: 17 Aug 2014
    7.5
    High

    CVE-2014-3904

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in lib/admin.php in tenfourzero Shutter 0.1.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Aug 2014
    7.8
    High

    CVE-2014-7145

    Last Modified: 12 Apr 2025

    The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during resolution of DFS referrals.

    Published: 17 Aug 2014
    4.3
    Medium

    CVE-2013-7144

    Last Modified: 12 Apr 2025

    LINE 3.2.1.83 and earlier on Windows and 3.2.1 and earlier on OS X does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 Aug 2014
    4.3
    Medium

    CVE-2014-0852

    Last Modified: 12 Apr 2025

    IBM WebSphere DataPower SOA appliances through 4.0.2.15, 5.x through 5.0.0.17, 6.0.0.x through 6.0.0.9, and 6.0.1.x through 6.0.1.5 make it easier for remote attackers to obtain a PreMasterSecret value and defeat cryptographic protection mechanisms by sending a large number of requests in an SSL/TLS side-channel timing attack.

    Published: 16 Aug 2014
    6.3
    Medium

    CVE-2014-5260

    Last Modified: 12 Apr 2025

    The (1) mkxmltype and (2) mkdtskel scripts in XML-DT before 0.64 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_xml_##### temporary file.

    Published: 16 Aug 2014
    7.8
    High

    CVE-2013-7180

    Last Modified: 12 Apr 2025

    Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly restrict password recovery, which allows attackers to obtain administrative privileges by leveraging physical access or terminal access to spoof a reset code.

    Published: 15 Aug 2014