CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2014-0328

    Last Modified: 12 Apr 2025

    The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send an SNMP request and a TFTP response.

    Published: 15 Aug 2014
    5.8
    Medium

    CVE-2014-3902

    Last Modified: 12 Apr 2025

    The CyberAgent Ameba application 3.x and 4.x before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 Aug 2014
    10
    Critical

    CVE-2014-2940

    Last Modified: 12 Apr 2025

    Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator account, which allows attackers to obtain administrative control by leveraging physical access or terminal access.

    Published: 15 Aug 2014
    7.1
    High

    CVE-2014-2941

    Last Modified: 12 Apr 2025

    Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 command. NOTE: the vendor reportedly states "there is no possibility to exploit another user's credentials.

    Published: 15 Aug 2014
    Unknown

    CVE-2014-2943

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2886, CVE-2014-2942. Reason: this ID was intended for one issue, but was assigned to two issues by a CNA. Notes: All CVE users should consult CVE-2014-2886 and CVE-2014-2942 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Aug 2014
    6.9
    Medium

    CVE-2014-2964

    Last Modified: 12 Apr 2025

    Cobham Aviator 700D and 700E satellite terminals have hardcoded passwords for the (1) debug, (2) prod, (3) do160, and (4) flrp programs, which allows physically proximate attackers to gain privileges by sending a password over a serial line.

    Published: 15 Aug 2014
    4
    Medium

    CVE-2014-6414

    Last Modified: 12 Apr 2025

    OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.

    Published: 15 Aug 2014
    6.5
    Medium

    CVE-2014-8750

    Last Modified: 12 Apr 2025

    Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.

    Published: 15 Aug 2014
    4.3
    Medium

    CVE-2014-5248

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to video MyCode.

    Published: 14 Aug 2014
    7.5
    High

    CVE-2014-5249

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the "Biblio self autocomplete" submodule in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Aug 2014
    7.5
    High

    CVE-2014-5250

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the AJAX autocompletion callback in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to access data via unspecified vectors.

    Published: 14 Aug 2014
    6.5
    Medium

    CVE-2012-0939

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in TestLink 1.8.5b and earlier allow remote authenticated users with the Requirement view permission to execute arbitrary SQL commands via the req_spec_id parameter to (1) reqSpecAnalyse.php, (2) reqSpecPrint.php, or (3) reqSpecView.php in requirements/. NOTE: some of these details are obtained from third party information.

    Published: 14 Aug 2014
    7.5
    High

    CVE-2012-3820

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Campaign11.exe in Arial Software Campaign Enterprise before 11.0.551 allow remote attackers to execute arbitrary SQL commands via the (1) SerialNumber field to activate.asp or (2) UID field to User-Edit.asp.

    Published: 14 Aug 2014
    7.5
    High

    CVE-2012-5685

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the inEmailAddress parameter in an UpdateClient action in the manage_clients module to the default URI.

    Published: 14 Aug 2014
    7.5
    High

    CVE-2012-6654

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) resetkey or (2) inConfEmail parameter to index.php, a different vulnerability than CVE-2012-5685.

    Published: 14 Aug 2014
    6.5
    Medium

    CVE-2012-0938

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with certain permissions to execute arbitrary SQL commands via the root_node parameter in the display_children function to (1) getrequirementnodes.php or (2) gettprojectnodes.php in lib/ajax/; the (3) cfield_id parameter in an edit action to lib/cfields/cfieldsEdit.php; the (4) id parameter in an edit action or (5) plan_id parameter in a create action to lib/plan/planMilestonesEdit.php; or the req_spec_id parameter to (6) reqImport.php or (7) in a create action to reqEdit.php in lib/requirements/. NOTE: some of these details are obtained from third party information.

    Published: 14 Aug 2014
    6.8
    Medium

    CVE-2012-5683

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) create new FTP users via a CreateFTP action in the ftp_management module to the default URI, (2) conduct cross-site scripting (XSS) attacks via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/, or (3) conduct SQL injection attacks via the inEmailAddress parameter in an UpdateClient action in the manage_clients module to the default URI.

    Published: 14 Aug 2014
    4.3
    Medium

    CVE-2012-5684

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the inFullname parameter in an UpdateAccountSettings action in the my_account module to zpanel/.

    Published: 14 Aug 2014
    6.8
    Medium

    CVE-2014-1385

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.

    Published: 14 Aug 2014
    6.8
    Medium

    CVE-2014-1384

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.

    Published: 14 Aug 2014
    6.8
    Medium

    CVE-2014-1386

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.

    Published: 14 Aug 2014
    6.8
    Medium

    CVE-2014-1387

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.

    Published: 14 Aug 2014
    6.8
    Medium

    CVE-2014-1388

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.

    Published: 14 Aug 2014
    6.8
    Medium

    CVE-2014-1389

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.

    Published: 14 Aug 2014
    6.8
    Medium

    CVE-2014-1390

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in HT6367.

    Published: 14 Aug 2014
    4.3
    Medium

    CVE-2014-1546

    Last Modified: 12 Apr 2025

    The response function in the JSONP endpoint in WebService/Server/JSONRPC.pm in jsonrpc.cgi in Bugzilla 3.x and 4.x before 4.0.14, 4.1.x and 4.2.x before 4.2.10, 4.3.x and 4.4.x before 4.4.5, and 4.5.x before 4.5.5 accepts certain long callback values and does not restrict the initial bytes of a JSONP response, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and obtain sensitive information, via a crafted OBJECT element with SWF content consistent with the _bz_callback character set.

    Published: 14 Aug 2014
    4.3
    Medium

    CVE-2014-1980

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in include/functions_metadata.inc.php in Piwigo before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the Make field in IPTC Exif metadata within an image uploaded to the Community plugin.

    Published: 14 Aug 2014
    4.3
    Medium

    CVE-2014-3898

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Fujitsu ServerView Operations Manager 5.00.09 through 6.30.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Aug 2014
    4
    Medium

    CVE-2014-5239

    Last Modified: 12 Apr 2025

    The Microsoft Outlook.com application before 7.8.2.12.49.7090 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 14 Aug 2014
    4.3
    Medium

    CVE-2012-6153

    Last Modified: 12 Apr 2025

    http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.

    Published: 14 Aug 2014
    5
    Medium

    CVE-2013-0334

    Last Modified: 12 Apr 2025

    Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.

    Published: 14 Aug 2014
    5
    Medium

    CVE-2014-6426

    Last Modified: 12 Apr 2025

    The dissect_hip_tlv function in epan/dissectors/packet-hip.c in the HIP dissector in Wireshark 1.12.x before 1.12.1 does not properly handle a NULL tree, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 14 Aug 2014
    5
    Medium

    CVE-2014-6427

    Last Modified: 12 Apr 2025

    Off-by-one error in the is_rtsp_request_or_reply function in epan/dissectors/packet-rtsp.c in the RTSP dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 allows remote attackers to cause a denial of service (application crash) via a crafted packet that triggers parsing of a token located one position beyond the current position.

    Published: 14 Aug 2014
    Unknown

    CVE-2014-5157

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5196. Reason: This candidate is a reservation duplicate of CVE-2014-5196. Notes: All CVE users should reference CVE-2014-5196 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Aug 2014
    7.5
    High

    CVE-2014-3165

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in modules/websockets/WorkerThreadableWebSocketChannel.cpp in the Web Sockets implementation in Blink, as used in Google Chrome before 36.0.1985.143, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an unexpectedly long lifetime of a temporary object during method completion.

    Published: 13 Aug 2014
    4.3
    Medium

    CVE-2014-3166

    Last Modified: 12 Apr 2025

    The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtain sensitive information by leveraging the use of multiple domain names.

    Published: 13 Aug 2014
    7.5
    High

    CVE-2014-3167

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.143 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 13 Aug 2014
    5.9
    Medium

    CVE-2014-3603

    Last Modified: 21 Nov 2024

    The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 13 Aug 2014
    5
    Medium

    CVE-2014-0136

    Last Modified: 12 Apr 2025

    The (1) get and (2) log methods in the AgentController in Red Hat CloudForms 3.0 Management Engine (CFME) 5.x allow remote attackers to insert arbitrary text into log files via unspecified vectors.

    Published: 13 Aug 2014
    5
    Medium

    CVE-2014-3589

    Last Modified: 12 Apr 2025

    PIL/IcnsImagePlugin.py in Python Imaging Library (PIL) and Pillow before 2.3.2 and 2.5.x before 2.5.2 allows remote attackers to cause a denial of service via a crafted block size.

    Published: 13 Aug 2014
    4.3
    Medium

    CVE-2014-3595

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.

    Published: 13 Aug 2014
    5
    Medium

    CVE-2014-6424

    Last Modified: 12 Apr 2025

    The dissect_v9_v10_pdu_data function in epan/dissectors/packet-netflow.c in the Netflow dissector in Wireshark 1.10.x before 1.10.10 and 1.12.x before 1.12.1 refers to incorrect offset and start variables, which allows remote attackers to cause a denial of service (uninitialized memory read and application crash) via a crafted packet.

    Published: 13 Aug 2014
    6.1
    Medium

    CVE-2014-3592

    Last Modified: 21 Nov 2024

    OpenShift Origin: Improperly validated team names could allow stored XSS attacks

    Published: 13 Aug 2014
    4
    Medium

    CVE-2014-1222

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter in a download action. NOTE: it is likely that this issue is actually in the KCFinder third-party component, and it affects additional products besides Vtiger CRM.

    Published: 12 Aug 2014
    8.5
    High

    CVE-2014-3338

    Last Modified: 12 Apr 2025

    The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly validate Kerberos SSO tokens, which allows remote authenticated users to gain privileges and execute arbitrary commands via crafted token data, aka Bug ID CSCum95491.

    Published: 12 Aug 2014
    6.5
    Medium

    CVE-2014-3339

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Server (CUPS) allow remote authenticated users to execute arbitrary SQL commands via crafted input to unspecified pages, aka Bug ID CSCup74290.

    Published: 12 Aug 2014
    7.8
    High

    CVE-2014-3901

    Last Modified: 12 Apr 2025

    Raritan Japan Dominion KX2-101 switches before 2 allow remote attackers to cause a denial of service (device hang) via a crafted packet.

    Published: 12 Aug 2014
    3.5
    Low

    CVE-2014-5202

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the search-value parameter.

    Published: 12 Aug 2014
    6.8
    Medium

    CVE-2014-3337

    Last Modified: 12 Apr 2025

    The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafted SIP message that is not properly handled during processing of an XML document, aka Bug ID CSCtq76428.

    Published: 12 Aug 2014
    8.8
    High

    CVE-2014-2817

    Last Modified: 22 Apr 2026

    Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."

    Published: 12 Aug 2014