CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-3328

    Last Modified: 12 Apr 2025

    The Intercluster Sync Agent Service in Cisco Unified Presence Server allows remote attackers to cause a denial of service via a TCP SYN flood, aka Bug ID CSCun34125.

    Published: 26 Jul 2014
    7.5
    High

    CVE-2014-4858

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field.

    Published: 26 Jul 2014
    9.3
    Critical

    CVE-2014-4979

    Last Modified: 12 Apr 2025

    Apple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed version number and flags in an mvhd atom.

    Published: 26 Jul 2014
    6
    Medium

    CVE-2014-2227

    Last Modified: 12 Apr 2025

    The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 does not restrict access to the application, which allows remote attackers to bypass the Same Origin Policy via a crafted SWF file.

    Published: 25 Jul 2014
    4.3
    Medium

    CVE-2014-5027

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via a query parameter to a diff fragment page.

    Published: 25 Jul 2014
    6.8
    Medium

    CVE-2014-5100

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new super user account via a request to admin/users/add, (2) insert cross-site scripting (XSS) sequences via the api_key_label parameter to admin/users/api-keys/1, or (3) disable file validation via a request to admin/settings/edit-security.

    Published: 25 Jul 2014
    4.3
    Medium

    CVE-2014-5101

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip, (9) TPL_phone, (10) TPL_pp_email, (11) TPL_authnet_id, (12) TPL_authnet_pass, (13) TPL_worldpay_id, (14) TPL_toocheckout_id, or (15) TPL_moneybookers_email in a first action to register.php or the (16) username parameter in a login action to user_login.php.

    Published: 25 Jul 2014
    7.5
    High

    CVE-2014-5102

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in vBulletin 5.0.4 through 5.1.3 Alpha 5 allows remote attackers to execute arbitrary SQL commands via the criteria[startswith] parameter to ajax/render/memberlist_items.

    Published: 25 Jul 2014
    4.3
    Medium

    CVE-2014-5103

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_security_check. Fixed in Version 10 Build 10000.

    Published: 25 Jul 2014
    4.9
    Medium

    CVE-2014-5252

    Last Modified: 12 Apr 2025

    The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.

    Published: 25 Jul 2014
    7.8
    High

    CVE-2014-2362

    Last Modified: 6 Oct 2025

    OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.

    Published: 24 Jul 2014
    7.2
    High

    CVE-2014-2361

    Last Modified: 6 Oct 2025

    OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.

    Published: 24 Jul 2014
    5
    Medium

    CVE-2014-2360

    Last Modified: 6 Oct 2025

    OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via packets that report a high battery voltage.

    Published: 24 Jul 2014
    4
    Medium

    CVE-2014-2370

    Last Modified: 6 Oct 2025

    Cross-site scripting (XSS) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to inject arbitrary web script or HTML via crafted data.

    Published: 24 Jul 2014
    4.6
    Medium

    CVE-2014-2369

    Last Modified: 6 Oct 2025

    Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

    Published: 24 Jul 2014
    6.8
    Medium

    CVE-2014-4686

    Last Modified: 12 Apr 2025

    The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.

    Published: 24 Jul 2014
    4.9
    Medium

    CVE-2014-4683

    Last Modified: 12 Apr 2025

    The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request.

    Published: 24 Jul 2014
    4.6
    Medium

    CVE-2014-4685

    Last Modified: 12 Apr 2025

    Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.

    Published: 24 Jul 2014
    4.3
    Medium

    CVE-2014-3110

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to inject arbitrary web script or HTML via invalid input.

    Published: 24 Jul 2014
    4.3
    Medium

    CVE-2014-2968

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI 11.001.08.00.03 allows remote attackers to inject arbitrary web script or HTML via an SMS message.

    Published: 24 Jul 2014
    10
    Critical

    CVE-2014-0607

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executable file.

    Published: 24 Jul 2014
    3.5
    Low

    CVE-2014-2971

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in AddStdLetter.jsp in MicroPact iComplaints before 8.0.2.1.8.8014 allows remote authenticated users to inject arbitrary web script or HTML via the description parameter.

    Published: 24 Jul 2014
    6.9
    Medium

    CVE-2014-1419

    Last Modified: 12 Apr 2025

    Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors.

    Published: 24 Jul 2014
    7.6
    High

    CVE-2014-2717

    Last Modified: 12 Apr 2025

    Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain administrative access by visiting the change-password page.

    Published: 24 Jul 2014
    6
    Medium

    CVE-2014-4684

    Last Modified: 12 Apr 2025

    The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.

    Published: 24 Jul 2014
    6.1
    Medium

    CVE-2014-3322

    Last Modified: 12 Apr 2025

    Cisco IOS XR 4.3(.2) and earlier on ASR 9000 devices does not properly perform NetFlow sampling of IP packets, which allows remote attackers to cause a denial of service (chip and card hangs) via malformed (1) IPv4 or (2) IPv6 packets, aka Bug ID CSCuo68417.

    Published: 24 Jul 2014
    5
    Medium

    CVE-2014-4682

    Last Modified: 12 Apr 2025

    The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.

    Published: 24 Jul 2014
    7.5
    High

    CVE-2014-4736

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.

    Published: 24 Jul 2014
    4.6
    Medium

    CVE-2014-4910

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in tools/backlight_helper.c in X.Org xf86-video-intel 2.99.911 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the interface name.

    Published: 24 Jul 2014
    7.8
    High

    CVE-2014-4927

    Last Modified: 12 Apr 2025

    Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.

    Published: 24 Jul 2014
    5
    Medium

    CVE-2014-5015

    Last Modified: 12 Apr 2025

    bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.

    Published: 24 Jul 2014
    4.3
    Medium

    CVE-2014-5024

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote attackers to inject arbitrary web script or HTML via the node_id parameter.

    Published: 24 Jul 2014
    9.8
    Critical

    CVE-2014-3527

    Last Modified: 20 Apr 2025

    When using the CAS Proxy ticket authentication from Spring Security 3.1 to 3.2.4 a malicious CAS Service could trick another CAS Service into authenticating a proxy ticket that was not associated. This is due to the fact that the proxy ticket authentication uses the information from the HttpServletRequest which is populated based upon untrusted information within the HTTP request. This means if there are access control restrictions on which CAS services can authenticate to one another, those restrictions can be bypassed. If users are not using CAS Proxy tickets and not basing access control decisions based upon the CAS Service, then there is no impact to users.

    Published: 24 Jul 2014
    5.5
    Medium

    CVE-2014-5118

    Last Modified: 21 Nov 2024

    Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability

    Published: 24 Jul 2014
    10
    Critical

    CVE-2014-4501

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions in util.c.

    Published: 23 Jul 2014
    9.3
    Critical

    CVE-2014-3939

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmap data in a PXD file.

    Published: 23 Jul 2014
    10
    Critical

    CVE-2014-4502

    Last Modified: 12 Apr 2025

    Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a mining.subscribe response and a crafted mining.notify request.

    Published: 23 Jul 2014
    9.3
    Critical

    CVE-2014-3938

    Last Modified: 12 Apr 2025

    Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based buffer overflow.

    Published: 23 Jul 2014
    4.3
    Medium

    CVE-2014-4503

    Last Modified: 12 Apr 2025

    The parse_notify function in util.c in sgminer before 4.2.2 and cgminer 3.3.0 through 4.0.1 allows man-in-the-middle attackers to cause a denial of service (application exit) via a crafted (1) bbversion, (2) prev_hash, (3) nbit, or (4) ntime parameter in a mining.notify action stratum message.

    Published: 23 Jul 2014
    5
    Medium

    CVE-2014-4980

    Last Modified: 12 Apr 2025

    The /server/properties resource in Tenable Web UI before 2.3.5 for Nessus 5.2.3 through 5.2.7 allows remote attackers to obtain sensitive information via the token parameter.

    Published: 23 Jul 2014
    10
    Critical

    CVE-2014-1551

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the FontTableRec destructor in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 on Windows allows remote attackers to execute arbitrary code via crafted use of fonts in MathML content, leading to improper handling of a DirectWrite font-face object.

    Published: 23 Jul 2014
    4.6
    Medium

    CVE-2014-2972

    Last Modified: 12 Apr 2025

    expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value.

    Published: 23 Jul 2014
    7.5
    High

    CVE-2014-3490

    Last Modified: 12 Apr 2025

    RESTEasy 2.3.1 before 2.3.8.SP2 and 3.x before 3.0.9, as used in Red Hat JBoss Enterprise Application Platform (EAP) 6.3.0, does not disable external entities when the resteasy.document.expand.entity.references parameter is set to false, which allows remote attackers to read arbitrary files and have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0818.

    Published: 23 Jul 2014
    4.9
    Medium

    CVE-2014-5251

    Last Modified: 12 Apr 2025

    The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.

    Published: 23 Jul 2014
    10
    Critical

    CVE-2014-4947

    Last Modified: 12 Apr 2025

    Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.

    Published: 22 Jul 2014
    6.4
    Medium

    CVE-2014-4948

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Citrix XenServer 6.2 Service Pack 1 and earlier allows attackers to cause a denial of service and obtain sensitive information by modifying the guest virtual hard disk (VHD).

    Published: 22 Jul 2014
    7.5
    High

    CVE-2014-4511

    Last Modified: 12 Apr 2025

    Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.

    Published: 22 Jul 2014
    5
    Medium

    CVE-2014-5019

    Last Modified: 12 Apr 2025

    The multisite feature in Drupal 6.x before 6.32 and 7.x before 7.29 allows remote attackers to cause a denial of service via a crafted HTTP Host header, related to determining which configuration file to use.

    Published: 22 Jul 2014
    4.3
    Medium

    CVE-2014-2385

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter to exclusion/configure or (4) text:EmailServer or (5) newListList:Email parameter to notification/configure.

    Published: 22 Jul 2014
    7.5
    High

    CVE-2013-7392

    Last Modified: 12 Apr 2025

    Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.

    Published: 22 Jul 2014