CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2014-4326

    Last Modified: 12 Apr 2025

    Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.

    Published: 22 Jul 2014
    5
    Medium

    CVE-2014-4911

    Last Modified: 12 Apr 2025

    The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.

    Published: 22 Jul 2014
    4.9
    Medium

    CVE-2014-5020

    Last Modified: 12 Apr 2025

    The File module in Drupal 7.x before 7.29 does not properly check permissions to view files, which allows remote authenticated users with certain permissions to bypass intended restrictions and read files by attaching the file to content with a file field.

    Published: 22 Jul 2014
    2.1
    Low

    CVE-2014-5021

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Form API in Drupal 6.x before 6.32 and possibly 7.x before 7.29 allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via an option group label.

    Published: 22 Jul 2014
    4.3
    Medium

    CVE-2014-5022

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Ajax system in Drupal 7.x before 7.29 allows remote attackers to inject arbitrary web script or HTML via vectors involving forms with an Ajax-enabled textfield and a file field.

    Published: 22 Jul 2014
    6.8
    Medium

    CVE-2014-5023

    Last Modified: 12 Apr 2025

    Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.

    Published: 22 Jul 2014
    9.3
    Critical

    CVE-2014-1557

    Last Modified: 25 Nov 2025

    The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a high-quality image.

    Published: 22 Jul 2014
    9.3
    Critical

    CVE-2014-1555

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.

    Published: 22 Jul 2014
    10
    Critical

    CVE-2014-1547

    Last Modified: 25 Nov 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 22 Jul 2014
    10
    Critical

    CVE-2014-1544

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a trust domain.

    Published: 22 Jul 2014
    5
    Medium

    CVE-2014-5031

    Last Modified: 12 Apr 2025

    The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.

    Published: 22 Jul 2014
    5.8
    Medium

    CVE-2014-1552

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote attackers to bypass intended restrictions on same-origin content via a crafted web site in conjunction with a redirect.

    Published: 22 Jul 2014
    4.3
    Medium

    CVE-2014-1559

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1558.

    Published: 22 Jul 2014
    6.8
    Medium

    CVE-2014-5263

    Last Modified: 12 Apr 2025

    vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause a denial of service (out-of-bounds access, infinite loop, and memory corruption) and possibly gain privileges via unspecified vectors.

    Published: 22 Jul 2014
    10
    Critical

    CVE-2014-1548

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 22 Jul 2014
    9.3
    Critical

    CVE-2014-1549

    Last Modified: 12 Apr 2025

    The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not properly allocate Web Audio buffer memory, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via crafted audio content that is improperly handled during playback buffering.

    Published: 22 Jul 2014
    10
    Critical

    CVE-2014-1550

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.

    Published: 22 Jul 2014
    4.3
    Medium

    CVE-2014-1558

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use UTF-8 character encoding in a required context, a different vulnerability than CVE-2014-1559.

    Published: 22 Jul 2014
    9.3
    Critical

    CVE-2014-1556

    Last Modified: 25 Nov 2025

    Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.

    Published: 22 Jul 2014
    5.8
    Medium

    CVE-2014-1561

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to alter the placement of UI icons via crafted JavaScript code that is encountered during (1) page, (2) panel, or (3) toolbar customization.

    Published: 22 Jul 2014
    4.3
    Medium

    CVE-2014-1560

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (X.509 certificate parsing outage) via a crafted certificate that does not use ASCII character encoding in a required context.

    Published: 22 Jul 2014
    2.1
    Low

    CVE-2014-7230

    Last Modified: 12 Apr 2025

    The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.

    Published: 22 Jul 2014
    2.1
    Low

    CVE-2014-7231

    Last Modified: 12 Apr 2025

    The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

    Published: 22 Jul 2014
    1.5
    Low

    CVE-2014-5029

    Last Modified: 12 Apr 2025

    The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3537.

    Published: 22 Jul 2014
    1.9
    Low

    CVE-2014-5030

    Last Modified: 12 Apr 2025

    CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.

    Published: 22 Jul 2014
    4.3
    Medium

    CVE-2014-5016

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to application/views/admin/globalSettings_view.php, or (3) a crafted CSV file to the "Import CSV" functionality.

    Published: 21 Jul 2014
    7.5
    High

    CVE-2014-5017

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter.

    Published: 21 Jul 2014
    4.3
    Medium

    CVE-2014-4734

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

    Published: 21 Jul 2014
    7.5
    High

    CVE-2014-4960

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

    Published: 21 Jul 2014
    4.3
    Medium

    CVE-2014-5018

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

    Published: 21 Jul 2014
    7.2
    High

    CVE-2014-3534

    Last Modified: 12 Apr 2025

    arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.

    Published: 21 Jul 2014
    4
    Medium

    CVE-2014-3555

    Last Modified: 12 Apr 2025

    OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.

    Published: 21 Jul 2014
    7.5
    High

    CVE-2014-8182

    Last Modified: 21 Nov 2024

    An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv backend, an attacker could crash the service with crafted DNS responses.

    Published: 21 Jul 2014
    3.5
    Low

    CVE-2014-1994

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Notices portlet in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Jul 2014
    3.5
    Low

    CVE-2014-4954

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the PMA_getHtmlForActionLinks function in libraries/structure.lib.php in phpMyAdmin 4.2.x before 4.2.6 allows remote authenticated users to inject arbitrary web script or HTML via a crafted table comment that is improperly handled during construction of a database structure page.

    Published: 20 Jul 2014
    4
    Medium

    CVE-2014-4987

    Last Modified: 12 Apr 2025

    server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.

    Published: 20 Jul 2014
    5
    Medium

    CVE-2014-1973

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the NextApp File Explorer application before 2.1.0.3 for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename.

    Published: 20 Jul 2014
    10
    Critical

    CVE-2014-1987

    Last Modified: 12 Apr 2025

    The CGI component in Cybozu Garoon 3.1.0 through 3.7 SP3 allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 20 Jul 2014
    3.5
    Low

    CVE-2014-1992

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Messages functionality in Cybozu Garoon 3.1.x, 3.5.x, and 3.7.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Jul 2014
    4
    Medium

    CVE-2014-1993

    Last Modified: 12 Apr 2025

    The Portlets subsystem in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

    Published: 20 Jul 2014
    3.5
    Low

    CVE-2014-1995

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Map search functionality in Cybozu Garoon 2.x and 3.x before 3.7 SP4 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Jul 2014
    7.5
    High

    CVE-2014-1996

    Last Modified: 12 Apr 2025

    Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbitrary code or cause a denial of service, via an API call.

    Published: 20 Jul 2014
    7.5
    High

    CVE-2014-1999

    Last Modified: 12 Apr 2025

    The auto-format feature in the Request_Curl class in FuelPHP 1.1 through 1.7.1 allows remote attackers to execute arbitrary code via a crafted response.

    Published: 20 Jul 2014
    4.3
    Medium

    CVE-2014-3885

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Webmin before 1.690 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.

    Published: 20 Jul 2014
    5
    Medium

    CVE-2014-3162

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.125 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 20 Jul 2014
    7.5
    High

    CVE-2014-3161

    Last Modified: 12 Apr 2025

    The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly interact with redirects, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that hosts a video stream.

    Published: 20 Jul 2014
    6.4
    Medium

    CVE-2014-3159

    Last Modified: 12 Apr 2025

    The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegate_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly restrict URL loading, which allows remote attackers to spoof the URL in the Omnibox via unspecified vectors.

    Published: 20 Jul 2014
    6.8
    Medium

    CVE-2014-3160

    Last Modified: 12 Apr 2025

    The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly restrict subresource requests associated with SVG files, which allows remote attackers to bypass the Same Origin Policy via a crafted file.

    Published: 20 Jul 2014
    4.3
    Medium

    CVE-2014-3884

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Usermin before 1.600 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.

    Published: 20 Jul 2014
    2.6
    Low

    CVE-2014-3886

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Webmin before 1.690, when referrer checking is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this might overlap CVE-2014-3924.

    Published: 20 Jul 2014