CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2014-3533

    Last Modified: 12 Apr 2025

    dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor.

    Published: 2 Jul 2014
    7.5
    High

    CVE-2014-3483

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql/quoting.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 4.x before 4.0.7 and 4.1.x before 4.1.3 allows remote attackers to execute arbitrary SQL commands by leveraging improper range quoting.

    Published: 2 Jul 2014
    6.5
    Medium

    CVE-2014-3520

    Last Modified: 12 Apr 2025

    OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for which the trustor has certain roles via the project ID in a V2 API trust token request.

    Published: 2 Jul 2014
    2.1
    Low

    CVE-2014-3532

    Last Modified: 12 Apr 2025

    dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message is forwarded.

    Published: 2 Jul 2014
    5.5
    Medium

    CVE-2014-3088

    Last Modified: 12 Apr 2025

    stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by replacing a text/plain .txt upload with an application/octet-stream .exe upload.

    Published: 1 Jul 2014
    3.5
    Low

    CVE-2013-3004

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.x and 7.2.x before 7.2.1.5 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 1 Jul 2014
    9.3
    Critical

    CVE-2013-7388

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed bitmap (BMP). NOTE: this issue was SPLIT from CVE-2013-3664 due to different affected products and codebases (ADT1).

    Published: 1 Jul 2014
    9.3
    Critical

    CVE-2013-3662

    Last Modified: 12 Apr 2025

    Timbre SketchUp (formerly Google SketchUp) before 8 Maintenance 2 allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers a stack-based buffer overflow.

    Published: 1 Jul 2014
    9.3
    Critical

    CVE-2013-3664

    Last Modified: 12 Apr 2025

    Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3662. NOTE: this issue was SPLIT due to different affected products and codebases (ADT1); CVE-2013-7388 has been assigned to the paintlib issue.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4533

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in ajax_functions.php in the GEO Redirector plugin 1.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the hid_id parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4584

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/editFacility.php in the wp-easybooking plugin 1.0.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the fID parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4520

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in phprack.php in the DMCA WaterMarker plugin before 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the plugin_dir parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4521

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in client-assist.php in the dsIDXpress IDX plugin before 2.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4575

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in js/window.php in the Wikipop plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4585

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WP-FaceThumb plugin possibly 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the ajax_url parameter to index.php.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4602

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in xencarousel-admin.js.php in the XEN Carousel plugin 0.12.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) path or (2) ajaxpath parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4513

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in server/offline.php in the ActiveHelper LiveHelp Live Chat plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MESSAGE, (2) EMAIL, or (3) NAME parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4515

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in mce_anyfont/dialog.php in the AnyFont plugin 2.2.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the text parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4516

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in bicm-carousel-preview.php in the BIC Media Widget plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the param parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4518

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in xd_resize.php in the Contact Form by ContactMe.com plugin 2.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4528

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in admin/swarm-settings.php in the Bugs Go Viral : Facebook Promotion Generator (fbpromotions) plugin 1.3.4 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) promo_type, (2) fb_edit_action, or (3) promo_id parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4538

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4545

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in pq_dialog.php in the Pro Quoter plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) leftorright or (2) author parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4556

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for eShop plugin 3.7.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4564

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in check.php in the Validated plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4569

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-4583

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in forms/messages.php in the WP-Contact (wp-contact-sidebar-widget) plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) edit, (2) order_direction, (3) limit_start, (4) id, or (5) order parameter.

    Published: 1 Jul 2014
    2.1
    Low

    CVE-2014-1348

    Last Modified: 12 Apr 2025

    Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mounting the data partition.

    Published: 1 Jul 2014
    3.6
    Low

    CVE-2014-1351

    Last Modified: 12 Apr 2025

    Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously.

    Published: 1 Jul 2014
    10
    Critical

    CVE-2014-1359

    Last Modified: 12 Apr 2025

    Integer underflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application.

    Published: 1 Jul 2014
    2.1
    Low

    CVE-2014-1360

    Last Modified: 12 Apr 2025

    Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1362

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-1369

    Last Modified: 12 Apr 2025

    WebKit in Apple Safari before 6.1.5 and 7.x before 7.0.5 allows user-assisted remote attackers to access file: URLs by leveraging a URL drag operation that originates at a crafted web site.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1382

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1349

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an invalid URL.

    Published: 1 Jul 2014
    2.1
    Low

    CVE-2014-1317

    Last Modified: 12 Apr 2025

    iBooks Commerce in Apple OS X before 10.9.4 places Apple ID credentials in the iBooks log, which allows local users to obtain sensitive information by reading this file.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1325

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-1345

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site.

    Published: 1 Jul 2014
    4.6
    Medium

    CVE-2014-1350

    Last Modified: 12 Apr 2025

    Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.

    Published: 1 Jul 2014
    1.9
    Low

    CVE-2014-1352

    Last Modified: 12 Apr 2025

    Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct brute-force passcode-guessing attacks via unspecified vectors.

    Published: 1 Jul 2014
    3.6
    Low

    CVE-2014-1353

    Last Modified: 12 Apr 2025

    Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode, which allows physically proximate attackers to bypass the lock protection mechanism, and access a certain foreground application, via unspecified vectors.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1354

    Last Modified: 12 Apr 2025

    CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image data.

    Published: 1 Jul 2014
    4.9
    Medium

    CVE-2014-1355

    Last Modified: 12 Apr 2025

    The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in IOReporting in Apple OS X before 10.9.4, allows local users to cause a denial of service (NULL pointer dereference and reboot) via crafted API arguments.

    Published: 1 Jul 2014
    10
    Critical

    CVE-2014-1356

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that sends IPC messages.

    Published: 1 Jul 2014
    10
    Critical

    CVE-2014-1357

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that generates log messages.

    Published: 1 Jul 2014
    10
    Critical

    CVE-2014-1358

    Last Modified: 12 Apr 2025

    Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1364

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1365

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1366

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1367

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.

    Published: 1 Jul 2014