CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2012-2052

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the U3D.8BI library plugin in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a long Collada asset element in a DAE file, as demonstrated by the cameraYFov value in the contributor comments element.

    Published: 19 Jun 2014
    5
    Medium

    CVE-2013-1068

    Last Modified: 12 Apr 2025

    The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.1 and 1:2014.1-0 before 1:2014.1-0ubuntu1.1 for Ubuntu 13.10 and 14.04 LTS does not properly set the sudo configuration, which makes it easier for attackers to gain privileges by leveraging another vulnerability.

    Published: 19 Jun 2014
    6.8
    Medium

    CVE-2014-3778

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboard Wireless Cable Modem allow remote attackers to hijack the authentication of administrators for requests that (1) change the dns service via the DdnsService parameter, (2) change the username via the DdnsUserName parameter, (3) change the password via the DdnsPassword parameter, or (4) change the host name via the DdnsHostName parameter.

    Published: 19 Jun 2014
    4.3
    Medium

    CVE-2014-4335

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) host or (2) password parameter to rtl/protected/admin/ddns/.

    Published: 19 Jun 2014
    6.8
    Medium

    CVE-2014-4155

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a request to Forms/tools_admin_1.

    Published: 19 Jun 2014
    4.3
    Medium

    CVE-2012-1621

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.02 allow remote attackers to inject arbitrary web script or HTML via (1) a parameter array in freemarker templates, the (2) contentId or (3) mapKey parameter in a cms event request, which are not properly handled in an error message, or unspecified input in (4) an ajax request to the getServerError function in checkoutProcess.js or (5) a Webslinger component request. NOTE: some of these details are obtained from third party information.

    Published: 19 Jun 2014
    4.3
    Medium

    CVE-2012-2569

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Synametrics Technologies Xeams 4.4 Build 5720 allows remote attackers to inject arbitrary web script or HTML via the body of an email.

    Published: 19 Jun 2014
    4.3
    Medium

    CVE-2012-2572

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ThreeWP Email Reflector plugin before 1.16 for WordPress allows remote attackers to inject arbitrary web script or HTML via the Subject of an email.

    Published: 19 Jun 2014
    5
    Medium

    CVE-2011-4367

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml or (2) the PATH_INFO to faces/javax.faces.resource/.

    Published: 19 Jun 2014
    6.5
    Medium

    CVE-2014-3810

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the members[] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-4333.

    Published: 19 Jun 2014
    6.8
    Medium

    CVE-2014-4333

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the members[] parameter, related to CVE-2014-3810.

    Published: 19 Jun 2014
    7.5
    High

    CVE-2014-4334

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Ubisoft Rayman Legends before 1.3.140380 allows remote attackers to execute arbitrary code via a long string in the "second connection" to TCP port 1001.

    Published: 19 Jun 2014
    4.3
    Medium

    CVE-2014-4329

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in lua/host_details.lua in ntopng 1.1 allows remote attackers to inject arbitrary web script or HTML via the host parameter.

    Published: 19 Jun 2014
    7.8
    High

    CVE-2014-2962

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

    Published: 19 Jun 2014
    5.8
    Medium

    CVE-2014-2001

    Last Modified: 12 Apr 2025

    The East Japan Railway Company JR East Japan application before 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.

    Published: 19 Jun 2014
    10
    Critical

    CVE-2014-2609

    Last Modified: 12 Apr 2025

    The Java Glassfish Admin Console in HP Executive Scorecard 9.40 and 9.41 does not require authentication, which allows remote attackers to execute arbitrary code via a session on TCP port 10001, aka ZDI-CAN-2116.

    Published: 19 Jun 2014
    7.1
    High

    CVE-2014-2610

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Content Acceleration Pack (CAP) web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code by uploading an executable file, aka ZDI-CAN-2117.

    Published: 19 Jun 2014
    9
    Critical

    CVE-2014-2611

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the fndwar web application in HP Executive Scorecard 9.40 and 9.41 allows remote authenticated users to execute arbitrary code, or obtain sensitive information or delete data, via unspecified vectors, aka ZDI-CAN-2120.

    Published: 19 Jun 2014
    9.3
    Critical

    CVE-2014-2782

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Published: 19 Jun 2014
    9.8
    Critical

    CVE-2014-4651

    Last Modified: 21 Nov 2024

    It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, cause a denial of service, or perform other attacks.

    Published: 19 Jun 2014
    5.5
    Medium

    CVE-2014-0203

    Last Modified: 12 Apr 2025

    The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.

    Published: 19 Jun 2014
    4.3
    Medium

    CVE-2014-3497

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.

    Published: 19 Jun 2014
    7.5
    High

    CVE-2015-8994

    Last Modified: 20 Apr 2025

    An issue was discovered in PHP 5.x and 7.x, when the configuration uses apache2handler/mod_php or php-fpm with OpCache enabled. With 5.x after 5.6.28 or 7.x after 7.0.13, the issue is resolved in a non-default configuration with the opcache.validate_permission=1 setting. The vulnerability details are as follows. In PHP SAPIs where PHP interpreters share a common parent process, Zend OpCache creates a shared memory object owned by the common parent during initialization. Child PHP processes inherit the SHM descriptor, using it to cache and retrieve compiled script bytecode ("opcode" in PHP jargon). Cache keys vary depending on configuration, but filename is a central key component, and compiled opcode can generally be run if a script's filename is known or can be guessed. Many common shared-hosting configurations change EUID in child processes to enforce privilege separation among hosted users (for example using mod_ruid2 for the Apache HTTP Server, or php-fpm user settings). In these scenarios, the default Zend OpCache behavior defeats script file permissions by sharing a single SHM cache among all child PHP processes. PHP scripts often contain sensitive information: Think of CMS configurations where reading or running another user's script usually means gaining privileges to the CMS database.

    Published: 19 Jun 2014
    Unknown

    CVE-2014-4286

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4286. Reason: This candidate is a duplicate of CVE-2013-4286. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2013-4286 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2012-2592

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Axigen Mail Server 8.0.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.

    Published: 18 Jun 2014
    9.8
    Critical

    CVE-2013-5017

    Last Modified: 12 Apr 2025

    SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 18 Jun 2014
    5.2
    Medium

    CVE-2014-1650

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in user.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 18 Jun 2014
    5.8
    Medium

    CVE-2014-1651

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in clientreport.php in the management console in Symantec Web Gateway (SWG) before 5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 18 Jun 2014
    2.3
    Low

    CVE-2014-1652

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec Web Gateway (SWG) before 5.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified report parameters.

    Published: 18 Jun 2014
    10
    Critical

    CVE-2014-4151

    Last Modified: 12 Apr 2025

    The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to create arbitrary files and execute arbitrary code via a crafted set_file request.

    Published: 18 Jun 2014
    10
    Critical

    CVE-2014-4152

    Last Modified: 12 Apr 2025

    The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to execute arbitrary code via a crafted remote_task request, related to injecting an ssh public key.

    Published: 18 Jun 2014
    7.8
    High

    CVE-2014-4153

    Last Modified: 12 Apr 2025

    The av-centerd SOAP service in AlienVault OSSIM before 4.8.0 allows remote attackers to read arbitrary files via a crafted get_file request.

    Published: 18 Jun 2014
    10
    Critical

    CVE-2014-0598

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-0599

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Jun 2014
    3.5
    Low

    CVE-2014-0910

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0 through 7.0.0.2 CF28 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-2779

    Last Modified: 12 Apr 2025

    mpengine.dll in Microsoft Malware Protection Engine before 1.1.10701.0 allows remote attackers to cause a denial of service (system hang) via a crafted file.

    Published: 18 Jun 2014
    3.5
    Low

    CVE-2014-3012

    Last Modified: 12 Apr 2025

    Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters to custom JSPs.

    Published: 18 Jun 2014
    3.5
    Low

    CVE-2014-3013

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Curam Social Program Management 4.5 SP10 through 6.0.5.4 allow remote authenticated users to inject arbitrary web script or HTML via crafted input to a (1) custom JSP or (2) custom renderer.

    Published: 18 Jun 2014
    10
    Critical

    CVE-2013-6221

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031.

    Published: 18 Jun 2014
    2.6
    Low

    CVE-2014-2000

    Last Modified: 12 Apr 2025

    The NTT 050 plus application before 4.2.1 for Android allows attackers to obtain sensitive information by leveraging the ability to read system log files.

    Published: 18 Jun 2014
    4
    Medium

    CVE-2014-2151

    Last Modified: 12 Apr 2025

    The WebVPN portal in Cisco Adaptive Security Appliance (ASA) Software 8.4(.7.15) and earlier allows remote authenticated users to obtain sensitive information via a crafted JavaScript file, aka Bug ID CSCui04520.

    Published: 18 Jun 2014
    6.5
    Medium

    CVE-2014-2949

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-3877

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in Frams' Fast File EXchange (F*EX, aka fex) before fex-20140530 allows remote attackers to conduct cross-site scripting (XSS) attacks via the addto parameter to fup.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-4304

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in browse.php in SQL Buddy 1.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the table parameter.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-4308

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) before 6.5.5 allow remote attackers to inject arbitrary web script or HTML via the (1) USRLNM parameter to myaccount/mysettings.edit.validate.asp or the frame parameter to (2) iframe.picker.statchannels.asp, (3) iframe.picker.channelgroups.asp, (4) iframe.picker.extensions.asp, (5) iframe.picker.licenseusergroups.asp, (6) iframe.picker.licenseusers.asp, (7) iframe.picker.lookup.asp, or (8) iframe.picker.marks.asp in _ifr/.

    Published: 18 Jun 2014
    5
    Medium

    CVE-2014-4306

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files via a .. (dot dot) in the logfile parameter in a download action.

    Published: 18 Jun 2014
    9.3
    Critical

    CVE-2011-2592

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9.x before 9.3-57.5 and 10.0 before 10.0-69.4 allows remote attackers to execute arbitrary code via a long CSEC HTTP response header.

    Published: 18 Jun 2014
    2.1
    Low

    CVE-2014-4303

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Touch theme 7.x-1.x before 7.x-1.9 for Drupal allow remote authenticated users with the Administer themes permission to inject arbitrary web script or HTML via vectors related to the (1) Twitter and (2) Facebook username settings.

    Published: 18 Jun 2014
    7.5
    High

    CVE-2014-4305

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in NICE Recording eXpress (aka Cybertech eXpress) 6.5.7 and earlier allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 18 Jun 2014
    7.5
    High

    CVE-2014-4307

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in categories-x.php in WebTitan before 4.04 allows remote attackers to execute arbitrary SQL commands via the sortkey parameter.

    Published: 18 Jun 2014