CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2014-1368

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1370

    Last Modified: 12 Apr 2025

    The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive.

    Published: 1 Jul 2014
    7.5
    High

    CVE-2014-1371

    Last Modified: 12 Apr 2025

    Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message.

    Published: 1 Jul 2014
    4.9
    Medium

    CVE-2014-1372

    Last Modified: 12 Apr 2025

    Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call.

    Published: 1 Jul 2014
    10
    Critical

    CVE-2014-1373

    Last Modified: 12 Apr 2025

    Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL API call, which allows attackers to execute arbitrary code via a crafted application.

    Published: 1 Jul 2014
    2.1
    Low

    CVE-2014-1375

    Last Modified: 12 Apr 2025

    Intel Graphics Driver in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.

    Published: 1 Jul 2014
    10
    Critical

    CVE-2014-1376

    Last Modified: 12 Apr 2025

    Intel Compute in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenCL API call, which allows attackers to execute arbitrary code via a crafted application.

    Published: 1 Jul 2014
    10
    Critical

    CVE-2014-1379

    Last Modified: 12 Apr 2025

    Graphics Drivers in Apple OS X before 10.9.4 allows attackers to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a 32-bit executable file for a crafted application.

    Published: 1 Jul 2014
    2.6
    Low

    CVE-2014-1380

    Last Modified: 12 Apr 2025

    The Security - Keychain component in Apple OS X before 10.9.4 does not properly implement keystroke observers, which allows physically proximate attackers to bypass the screen-lock protection mechanism, and enter characters into an arbitrary window under the lock window, via keyboard input.

    Published: 1 Jul 2014
    10
    Critical

    CVE-2014-1381

    Last Modified: 12 Apr 2025

    Thunderbolt in Apple OS X before 10.9.4 does not properly restrict IOThunderBoltController API calls, which allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted call.

    Published: 1 Jul 2014
    5.5
    Medium

    CVE-2014-1383

    Last Modified: 12 Apr 2025

    Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspecified vectors.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1340

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.5 and 7.x before 7.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1.

    Published: 1 Jul 2014
    5
    Medium

    CVE-2014-1361

    Last Modified: 12 Apr 2025

    Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only for a DTLS connection, which allows remote attackers to obtain potentially sensitive information from uninitialized process memory by providing a DTLS message within a TLS connection.

    Published: 1 Jul 2014
    6.8
    Medium

    CVE-2014-1363

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4.

    Published: 1 Jul 2014
    10
    Critical

    CVE-2014-1377

    Last Modified: 12 Apr 2025

    Array index error in IOAcceleratorFamily in Apple OS X before 10.9.4 allows attackers to execute arbitrary code via a crafted application.

    Published: 1 Jul 2014
    2.1
    Low

    CVE-2014-1378

    Last Modified: 12 Apr 2025

    IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object.

    Published: 1 Jul 2014
    7.2
    High

    CVE-2014-3499

    Last Modified: 12 Apr 2025

    Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

    Published: 1 Jul 2014
    5.4
    Medium

    CVE-2014-2509

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in the Report Advisor (RA) component in EMC Network Configuration Manager (NCM) before 9.3 allows remote attackers to hijack web sessions via a session cookie.

    Published: 1 Jul 2014
    3.5
    Low

    CVE-2014-2512

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Jul 2014
    4.3
    Medium

    CVE-2014-3489

    Last Modified: 12 Apr 2025

    lib/util/miq-password.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 uses a hard-coded salt, which makes it easier for remote attackers to guess passwords via a brute force attack.

    Published: 30 Jun 2014
    8.8
    High

    CVE-2014-3498

    Last Modified: 20 Apr 2025

    The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.

    Published: 30 Jun 2014
    5
    Medium

    CVE-2014-0180

    Last Modified: 12 Apr 2025

    The wait_for_task function in app/controllers/application_controller.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via unspecified vectors.

    Published: 30 Jun 2014
    4.9
    Medium

    CVE-2014-0184

    Last Modified: 12 Apr 2025

    Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 logs the root password when deploying a VM, which allows local users to obtain sensitive information by reading the evm.log file.

    Published: 30 Jun 2014
    4.3
    Medium

    CVE-2014-0176

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in application/panel_control in CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Jun 2014
    8.8
    High

    CVE-2014-0197

    Last Modified: 21 Nov 2024

    CFME: CSRF protection vulnerability via permissive check of the referrer header

    Published: 30 Jun 2014
    6.5
    Medium

    CVE-2015-5239

    Last Modified: 21 Nov 2024

    Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.

    Published: 30 Jun 2014
    4
    Medium

    CVE-2014-3485

    Last Modified: 12 Apr 2025

    The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

    Published: 30 Jun 2014
    6.9
    Medium

    CVE-2014-3486

    Last Modified: 12 Apr 2025

    The (1) shell_exec function in lib/util/MiqSshUtilV1.rb and (2) temp_cmd_file function in lib/util/MiqSshUtilV2.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 allow local users to execute arbitrary commands via a symlink attack on a temporary file with a predictable name.

    Published: 30 Jun 2014
    4.6
    Medium

    CVE-2014-4698

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in ext/spl/spl_array.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted ArrayIterator usage within applications in certain web-hosting environments.

    Published: 29 Jun 2014
    4.6
    Medium

    CVE-2014-4670

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in ext/spl/spl_dllist.c in the SPL component in PHP through 5.5.14 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact via crafted iterator usage within applications in certain web-hosting environments.

    Published: 29 Jun 2014
    10
    Critical

    CVE-2014-4648

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure."

    Published: 28 Jun 2014
    6.5
    Medium

    CVE-2014-4649

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field.

    Published: 28 Jun 2014
    4
    Medium

    CVE-2014-2612

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 28 Jun 2014
    9
    Critical

    CVE-2014-2613

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to gain privileges via unknown vectors.

    Published: 28 Jun 2014
    3.5
    Low

    CVE-2014-4669

    Last Modified: 12 Apr 2025

    HP Enterprise Maps 1.00 allows remote authenticated users to read arbitrary files via a WSDL document containing an XML external entity declaration in conjunction with an entity reference within a GetQuote operation, related to an XML External Entity (XXE) issue.

    Published: 28 Jun 2014
    4.3
    Medium

    CVE-2014-2006

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Jun 2014
    4.9
    Medium

    CVE-2013-6308

    Last Modified: 12 Apr 2025

    IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login credentials via an unspecified injection.

    Published: 28 Jun 2014
    6
    Medium

    CVE-2013-6309

    Last Modified: 12 Apr 2025

    IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct transactions, via an unspecified link injection.

    Published: 28 Jun 2014
    3.5
    Low

    CVE-2013-6310

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Jun 2014
    6.5
    Medium

    CVE-2013-6311

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Jun 2014
    5
    Medium

    CVE-2014-0891

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging incorrect request handling by the (1) Proxy or (2) ODR server.

    Published: 28 Jun 2014
    6.8
    Medium

    CVE-2014-3881

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 28 Jun 2014
    5
    Medium

    CVE-2014-3011

    Last Modified: 12 Apr 2025

    IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors.

    Published: 27 Jun 2014
    6.4
    Medium

    CVE-2011-1381

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown vectors.

    Published: 27 Jun 2014
    4.3
    Medium

    CVE-2014-3433

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management console in Symantec Data Insight 3.x and 4.x before 4.5 allows remote attackers to inject arbitrary web script or HTML via an unspecified form field, related to an "HTML script injection" issue.

    Published: 27 Jun 2014
    4.3
    Medium

    CVE-2014-3432

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management console in Symantec Data Insight 3.x and 4.x before 4.5 allows remote attackers to inject arbitrary web script or HTML via an unspecified form field.

    Published: 27 Jun 2014
    6.5
    Medium

    CVE-2014-3480

    Last Modified: 4 Dec 2025

    The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.

    Published: 27 Jun 2014
    6.5
    Medium

    CVE-2014-3478

    Last Modified: 4 Dec 2025

    Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.

    Published: 27 Jun 2014
    6.5
    Medium

    CVE-2014-0207

    Last Modified: 4 Dec 2025

    The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.

    Published: 27 Jun 2014
    5
    Medium

    CVE-2014-3538

    Last Modified: 12 Apr 2025

    file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.

    Published: 27 Jun 2014