CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2014-0236

    Last Modified: 12 Apr 2025

    file before 5.18, as used in the Fileinfo component in PHP before 5.6.0, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a zero root_storage value in a CDF file, related to cdf.c and readcdf.c.

    Published: 27 Jun 2014
    4.3
    Medium

    CVE-2014-3479

    Last Modified: 12 Apr 2025

    The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (application crash) via a crafted stream offset in a CDF file.

    Published: 27 Jun 2014
    4.3
    Medium

    CVE-2014-3487

    Last Modified: 12 Apr 2025

    The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (application crash) via a crafted CDF file.

    Published: 27 Jun 2014
    5
    Medium

    CVE-2014-4611

    Last Modified: 12 Apr 2025

    Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.

    Published: 26 Jun 2014
    5
    Medium

    CVE-2014-4341

    Last Modified: 12 Apr 2025

    MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.

    Published: 26 Jun 2014
    8.8
    High

    CVE-2014-4607

    Last Modified: 21 Nov 2024

    Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.

    Published: 26 Jun 2014
    7.3
    High

    CVE-2014-4608

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says "the Linux kernel is *not* affected; media hype.

    Published: 26 Jun 2014
    8.8
    High

    CVE-2014-4610

    Last Modified: 21 Nov 2024

    Integer overflow in the get_len function in libavutil/lzo.c in FFmpeg before 0.10.14, 1.1.x before 1.1.12, 1.2.x before 1.2.7, 2.0.x before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.4 allows remote attackers to execute arbitrary code via a crafted Literal Run.

    Published: 26 Jun 2014
    5.5
    Medium

    CVE-2014-4659

    Last Modified: 21 Nov 2024

    Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.

    Published: 26 Jun 2014
    5
    Medium

    CVE-2014-4342

    Last Modified: 12 Apr 2025

    MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.

    Published: 26 Jun 2014
    4.4
    Medium

    CVE-2016-1000236

    Last Modified: 21 Nov 2024

    Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.

    Published: 26 Jun 2014
    6.8
    Medium

    CVE-2014-4030

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that remove players via a delete action to wp-admin/admin.php.

    Published: 25 Jun 2014
    5
    Medium

    CVE-2014-4643

    Last Modified: 12 Apr 2025

    Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or (6) CDUP command.

    Published: 25 Jun 2014
    7.5
    High

    CVE-2014-4644

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 25 Jun 2014
    4.3
    Medium

    CVE-2014-4645

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in dhcpinfo.html in D-link DSL-2760U-E1 allows remote attackers to inject arbitrary web script or HTML via a hostname.

    Published: 25 Jun 2014
    6.8
    Medium

    CVE-2014-3299

    Last Modified: 12 Apr 2025

    Cisco IOS allows remote authenticated users to cause a denial of service (device reload) via malformed IPsec packets, aka Bug ID CSCui79745.

    Published: 25 Jun 2014
    6.8
    Medium

    CVE-2014-2005

    Last Modified: 12 Apr 2025

    Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforce intended authentication requirements for a resume action from sleep mode, which allows physically proximate attackers to obtain desktop access by leveraging the absence of a login screen.

    Published: 25 Jun 2014
    6.8
    Medium

    CVE-2014-3882

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Login rebuilder plugin before 1.2.0 for WordPress allows remote attackers to hijack the authentication of arbitrary users.

    Published: 25 Jun 2014
    7.3
    High

    CVE-2013-0165

    Last Modified: 21 Nov 2024

    cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.

    Published: 24 Jun 2014
    2.1
    Low

    CVE-2014-0206

    Last Modified: 12 Apr 2025

    Array index error in the aio_read_events_ring function in fs/aio.c in the Linux kernel through 3.15.1 allows local users to obtain sensitive information from kernel memory via a large head value.

    Published: 24 Jun 2014
    4.6
    Medium

    CVE-2014-4157

    Last Modified: 12 Apr 2025

    arch/mips/include/asm/thread_info.h in the Linux kernel before 3.14.8 on the MIPS platform does not configure _TIF_SECCOMP checks on the fast system-call path, which allows local users to bypass intended PR_SET_SECCOMP restrictions by executing a crafted application without invoking a trace or audit subsystem.

    Published: 23 Jun 2014
    2.7
    Low

    CVE-2014-3493

    Last Modified: 12 Apr 2025

    The push_ascii function in smbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) via an attempt to read a Unicode pathname without specifying use of Unicode, leading to a character-set conversion failure that triggers an invalid pointer dereference.

    Published: 23 Jun 2014
    10
    Critical

    CVE-2014-0247

    Last Modified: 12 Apr 2025

    LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.

    Published: 23 Jun 2014
    6.8
    Medium

    CVE-2014-0248

    Last Modified: 12 Apr 2025

    org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.

    Published: 23 Jun 2014
    9.8
    Critical

    CVE-2014-4650

    Last Modified: 21 Nov 2024

    The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

    Published: 23 Jun 2014
    2.6
    Low

    CVE-2014-4721

    Last Modified: 12 Apr 2025

    The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent attackers to obtain sensitive information from process memory by using the integer data type with crafted values, related to a "type confusion" vulnerability, as demonstrated by reading a private SSL key in an Apache HTTP Server web-hosting environment with mod_ssl and a PHP 5.3.x mod_php.

    Published: 23 Jun 2014
    5.5
    Medium

    CVE-2014-3471

    Last Modified: 21 Nov 2024

    Use-after-free vulnerability in hw/pci/pcie.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU instance crash) via hotplug and hotunplug operations of Virtio block devices.

    Published: 23 Jun 2014
    6.4
    Medium

    CVE-2014-7185

    Last Modified: 12 Apr 2025

    Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.

    Published: 23 Jun 2014
    8
    High

    CVE-2014-3053

    Last Modified: 12 Apr 2025

    The Local Management Interface (LMI) in IBM Security Access Manager (ISAM) for Mobile 8.0 with firmware 8.0.0.0 through 8.0.0.3 and IBM Security Access Manager for Web 7.0, and 8.0 with firmware 8.0.0.2 and 8.0.0.3, allows remote attackers to bypass authentication via a login action with invalid credentials.

    Published: 21 Jun 2014
    4
    Medium

    CVE-2013-6737

    Last Modified: 12 Apr 2025

    IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dump file upon encountering a 1691 hardware fault, which allows remote authenticated users to obtain sensitive customer-data fragments by reading this file after it is copied.

    Published: 21 Jun 2014
    10
    Critical

    CVE-2014-3073

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in IBM Security Access Manager (ISAM) for Mobile 8.0 and IBM Security Access Manager for Web 7.0 and 8.0 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 21 Jun 2014
    3.3
    Low

    CVE-2014-3052

    Last Modified: 12 Apr 2025

    The reverse-proxy feature in IBM Security Access Manager (ISAM) for Web 8.0 with firmware 8.0.0.2 and 8.0.0.3 interprets the jct-nist-compliance parameter in the opposite of the intended manner, which makes it easier for remote attackers to obtain sensitive information by leveraging weak SSL encryption settings that lack NIST SP 800-131A compliance.

    Published: 21 Jun 2014
    4
    Medium

    CVE-2014-3296

    Last Modified: 12 Apr 2025

    The XML programmatic interface (XML PI) in Cisco WebEx Meeting Server 1.5(.1.131) and earlier allows remote authenticated users to obtain sensitive meeting information via a crafted URL, aka Bug ID CSCum03527.

    Published: 21 Jun 2014
    4.3
    Medium

    CVE-2014-3431

    Last Modified: 12 Apr 2025

    Symantec PGP Desktop 10.x, and Encryption Desktop Professional 10.3.x before 10.3.2 MP2, on OS X uses world-writable permissions for temporary files, which allows local users to bypass intended restrictions on file reading, modification, creation, and permission changes via unspecified vectors.

    Published: 21 Jun 2014
    6.8
    Medium

    CVE-2014-3883

    Last Modified: 12 Apr 2025

    Usermin before 1.600 allows remote attackers to execute arbitrary operating-system commands via unspecified vectors related to a user action.

    Published: 21 Jun 2014
    4.6
    Medium

    CVE-2014-4509

    Last Modified: 12 Apr 2025

    The MKDQUOTESAFE function in the Fan-out driver scripts in Fan-Out Platform Services in Novell Identity Manager (aka IDM) 4.0.2 allows local users to execute arbitrary commands by leveraging eDirectory POSIX attribute changes to insert shell metacharacters.

    Published: 21 Jun 2014
    5
    Medium

    CVE-2014-5163

    Last Modified: 12 Apr 2025

    The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors in Wireshark 1.10.x before 1.10.9 does not completely initialize a certain buffer, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 21 Jun 2014
    10
    Critical

    CVE-2012-5106

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via a long string in a PUT command.

    Published: 20 Jun 2014
    4.3
    Medium

    CVE-2012-2579

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the WP SimpleMail plugin 1.0.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) To, (2) From, (3) Date, or (4) Subject field of an email.

    Published: 20 Jun 2014
    4.3
    Medium

    CVE-2012-2580

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.

    Published: 20 Jun 2014
    5
    Medium

    CVE-2011-4821

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the TFTP server in D-Link DIR-601 Wireless N150 Home Router with firmware 1.02NA allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 20 Jun 2014
    4.3
    Medium

    CVE-2012-2591

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EmailArchitect Email Server 10.0 and 10.0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) From or (2) Date field in an email.

    Published: 20 Jun 2014
    2.1
    Low

    CVE-2014-4506

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Custom Meta module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer custom meta settings" permission to inject arbitrary web script or HTML via the (1) attribute or (2) content value for a meta tag.

    Published: 20 Jun 2014
    4.3
    Medium

    CVE-2014-4505

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Easy Breadcrumb module 7.x-2.x before 7.x-2.10 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Jun 2014
    6.4
    Medium

    CVE-2014-4507

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the dst parameter to tftp/fetch_boot_file.

    Published: 20 Jun 2014
    7.5
    High

    CVE-2012-0273

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in MinaliC 2.0.0 allow remote attackers to execute arbitrary code via a (1) session_id cookie in a request to the get_cookie_value function in response.c, (2) directory name in a request to the add_default_file function in response.c, or (3) file name in a request to the retrieve_physical_file_name_or_brows function in response.c.

    Published: 20 Jun 2014
    3.5
    Low

    CVE-2014-4348

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table name that is improperly handled after presence in (a) the favorite list or (b) recent tables.

    Published: 20 Jun 2014
    3.5
    Low

    CVE-2014-4349

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.1.x before 4.1.14.1 and 4.2.x before 4.2.4 allow remote authenticated users to inject arbitrary web script or HTML via a crafted table name that is improperly handled after a (1) hide or (2) unhide action.

    Published: 20 Jun 2014
    5
    Medium

    CVE-2014-4617

    Last Modified: 12 Apr 2025

    The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte sequence.

    Published: 20 Jun 2014
    5
    Medium

    CVE-2014-9640

    Last Modified: 12 Apr 2025

    oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

    Published: 20 Jun 2014