CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2014-4247

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.

    Published: 15 Jul 2014
    9.3
    Critical

    CVE-2014-4262

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Published: 15 Jul 2014
    4
    Medium

    CVE-2014-4263

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u65, 6u75, 7u60, and 8u5, and JRockit R27.8.2 and R28.3.2, allows remote attackers to affect confidentiality and integrity via unknown vectors related to "Diffie-Hellman key agreement."

    Published: 15 Jul 2014
    5
    Medium

    CVE-2014-4264

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect availability via unknown vectors related to Security.

    Published: 15 Jul 2014
    5
    Medium

    CVE-2014-4266

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u60 and 8u5 allows remote attackers to affect integrity via unknown vectors related to Serviceability.

    Published: 15 Jul 2014
    6.8
    Medium

    CVE-2014-3319

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10.0(1) allows remote authenticated users to read arbitrary files via a crafted URL, aka Bug ID CSCup57676.

    Published: 14 Jul 2014
    1.7
    Low

    CVE-2014-2926

    Last Modified: 12 Apr 2025

    kapfa.sys in Kaseya Virtual System Administrator (VSA) 6.5 before 6.5.0.17 and 7.0 before 7.0.0.16 allows local users to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.

    Published: 14 Jul 2014
    5.4
    Medium

    CVE-2013-5567

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overlapping criteria for filtering and inspection, allows remote attackers to cause a denial of service (traffic loop and device crash) via a packet that triggers multiple matches, aka Bug ID CSCui45606.

    Published: 14 Jul 2014
    6.8
    Medium

    CVE-2013-6691

    Last Modified: 12 Apr 2025

    The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote CIFS servers to cause a denial of service (device reload) via a long share list, aka Bug ID CSCuj83344.

    Published: 14 Jul 2014
    7.8
    High

    CVE-2014-2950

    Last Modified: 12 Apr 2025

    Datum Systems SnIP on PSM-500 and PSM-4500 devices does not require authentication for FTP sessions, which allows remote attackers to obtain sensitive information via RETR commands.

    Published: 14 Jul 2014
    10
    Critical

    CVE-2014-2951

    Last Modified: 12 Apr 2025

    Datum Systems SnIP on PSM-500 and PSM-4500 devices has a hardcoded password of admin for the admin account, which makes it easier for remote attackers to obtain access via unspecified vectors.

    Published: 14 Jul 2014
    10
    Critical

    CVE-2014-2955

    Last Modified: 12 Apr 2025

    Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.

    Published: 14 Jul 2014
    5.5
    Medium

    CVE-2014-3317

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a crafted URL, aka Bug ID CSCup76314.

    Published: 14 Jul 2014
    4.9
    Medium

    CVE-2014-4013

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Policy Manager in Aruba Networks ClearPass 5.x, 6.0.x, 6.1.x through 6.1.4.61696, 6.2.x through 6.2.6.62196, and 6.3.x before 6.3.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Jul 2014
    6.5
    Medium

    CVE-2014-4944

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php.

    Published: 14 Jul 2014
    4.3
    Medium

    CVE-2014-4945

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via an unspecified flag in the basic (1) mailbox or (2) message view.

    Published: 14 Jul 2014
    4.3
    Medium

    CVE-2014-4946

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitrary web script or HTML via (1) unspecified flags or (2) a mailbox name in the dynamic mailbox view.

    Published: 14 Jul 2014
    7.5
    High

    CVE-2014-5119

    Last Modified: 12 Apr 2025

    Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.

    Published: 14 Jul 2014
    1.2
    Low

    CVE-2014-3537

    Last Modified: 12 Apr 2025

    The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.

    Published: 14 Jul 2014
    7.8
    High

    CVE-2014-3815

    Last Modified: 12 Apr 2025

    Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to cause a denial of service (flowd crash) via a crafted SIP packet.

    Published: 11 Jul 2014
    7.8
    High

    CVE-2014-3817

    Last Modified: 12 Apr 2025

    Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to cause a denial of service (flowd hang or crash) via a crafted packet.

    Published: 11 Jul 2014
    5.4
    Medium

    CVE-2014-3822

    Last Modified: 12 Apr 2025

    Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 before 12.1X46-D10, and 12.1X47 before 12.1X47-D10 on SRX Series devices, allows remote attackers to cause a denial of service (flowd crash) via a malformed packet, related to translating IPv6 to IPv4.

    Published: 11 Jul 2014
    4.3
    Medium

    CVE-2014-4738

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in FortiGuard FortiWeb 5.0.x, 5.1.x, and 5.2.x before 5.2.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) user/ldap_user/check_dlg or (2) user/radius_user/check_dlg.

    Published: 11 Jul 2014
    9
    Critical

    CVE-2014-3816

    Last Modified: 12 Apr 2025

    Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R11, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R8-S2, 12.3 before 12.3R7, 13.1 before 13.1R4-S2, 13.2 before 13.2R5, 13.3 before 13.3R2-S2, and 14.1 before 14.1R1 allows remote authenticated users to gain privileges via unspecified combinations of CLI commands and arguments.

    Published: 11 Jul 2014
    5
    Medium

    CVE-2014-4937

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 11 Jul 2014
    7.8
    High

    CVE-2014-3819

    Last Modified: 12 Apr 2025

    Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R10, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R8, 12.3 before 12.3R7, 13.1 before 13.1R4, 13.2 before 13.2R4, 13.3 before 13.3R2, and 14.1 before 14.1R1, when Auto-RP is enabled, allows remote attackers to cause a denial of service (RDP routing process crash and restart) via a malformed PIM packet.

    Published: 11 Jul 2014
    4.3
    Medium

    CVE-2014-3821

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in SRX Web Authentication (webauth) in Juniper Junos 11.4 before 11.4R11, 12.1X44 before 12.1X44-D34, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Jul 2014
    7.5
    High

    CVE-2014-4938

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in the wrp-add-new page to wp-admin/admin.php.

    Published: 11 Jul 2014
    6.5
    Medium

    CVE-2014-4939

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the enl-add-new page to wp-admin/admin.php.

    Published: 11 Jul 2014
    5
    Medium

    CVE-2014-4940

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.

    Published: 11 Jul 2014
    5
    Medium

    CVE-2014-4941

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a full pathname in the rss parameter to proxy.php.

    Published: 11 Jul 2014
    5
    Medium

    CVE-2014-4942

    Last Modified: 12 Apr 2025

    The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function.

    Published: 11 Jul 2014
    7.5
    High

    CVE-2013-6117

    Last Modified: 12 Apr 2025

    Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

    Published: 11 Jul 2014
    4.3
    Medium

    CVE-2014-3991

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) dol_use_jmobile, (2) dol_optimize_smallscreen, (3) dol_no_mouse_hover, (4) dol_hide_topmenu, (5) dol_hide_leftmenu, (6) mainmenu, or (7) leftmenu parameter to index.php; the (8) dol_use_jmobile, (9) dol_optimize_smallscreen, (10) dol_no_mouse_hover, (11) dol_hide_topmenu, or (12) dol_hide_leftmenu parameter to user/index.php; the (13) dol_use_jmobile, (14) dol_optimize_smallscreen, (15) dol_no_mouse_hover, (16) dol_hide_topmenu, or (17) dol_hide_leftmenu parameter to user/logout.php; the (18) email, (19) firstname, (20) job, (21) lastname, or (22) login parameter in an update action in a "User Card" to user/fiche.php; or the (23) modulepart or (24) file parameter to viewimage.php.

    Published: 11 Jul 2014
    5
    Medium

    CVE-2014-3503

    Last Modified: 12 Apr 2025

    Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

    Published: 11 Jul 2014
    6.5
    Medium

    CVE-2014-3992

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entity parameter in an update action to user/fiche.php or (2) sortorder parameter to user/group/index.php.

    Published: 11 Jul 2014
    4.9
    Medium

    CVE-2014-4700

    Last Modified: 12 Apr 2025

    Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors.

    Published: 11 Jul 2014
    4.3
    Medium

    CVE-2014-4907

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.

    Published: 11 Jul 2014
    4.3
    Medium

    CVE-2014-4908

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper handling within an http-equiv="refresh" META element.

    Published: 11 Jul 2014
    7.5
    High

    CVE-2013-4120

    Last Modified: 21 Nov 2024

    Katello has a Denial of Service vulnerability in API OAuth authentication

    Published: 11 Jul 2014
    5.4
    Medium

    CVE-2013-2101

    Last Modified: 21 Nov 2024

    Katello has multiple XSS issues in various entities

    Published: 11 Jul 2014
    6.5
    Medium

    CVE-2014-0026

    Last Modified: 21 Nov 2024

    katello-headpin is vulnerable to CSRF in REST API

    Published: 11 Jul 2014
    6.1
    Medium

    CVE-2014-0029

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the SAM web application in Red Hat katello-headpin allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 11 Jul 2014
    5.4
    Medium

    CVE-2013-0283

    Last Modified: 21 Nov 2024

    Katello: Username in Notification page has cross site scripting

    Published: 11 Jul 2014
    8.8
    High

    CVE-2013-4225

    Last Modified: 21 Nov 2024

    The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.

    Published: 11 Jul 2014
    6.1
    Medium

    CVE-2014-0183

    Last Modified: 21 Nov 2024

    Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.

    Published: 11 Jul 2014
    5.4
    Medium

    CVE-2014-3531

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.

    Published: 11 Jul 2014
    7.5
    High

    CVE-2015-2327

    Last Modified: 12 Apr 2025

    PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.

    Published: 11 Jul 2014
    4.3
    Medium

    CVE-2014-4855

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Polylang plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to a user description. NOTE: some of these details are obtained from third party information.

    Published: 10 Jul 2014
    7.5
    High

    CVE-2014-4852

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 10 Jul 2014