CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2014-4309

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Openfiler 2.99 allow remote attackers to inject arbitrary web script or HTML via the (1) TinkerAjax parameter to uptime.html, or remote authenticated users to inject arbitrary web script or HTML via the (2) MaxInstances, (3) PassivePorts, (4) Port, (5) ServerName, (6) TimeoutLogin, (7) TimeoutNoTransfer, or (8) TimeoutStalled parameter to admin/services_ftp.html; the (9) dns1 or (10) dns2 parameter to admin/system.html; the (11) newTgtName parameter to admin/volumes_iscsi_targets.html; the User-Agent HTTP header to (12) language.html, (13) login.html, or (14) password.html in account/; or the User-Agent HTTP header to (15) account_groups.html, (16) account_users.html, (17) services.html, (18) services_ftp.html, (19) services_iscsi_target.html, (20) services_rsync.html, (21) system_clock.html, (22) system_info.html, (23) system_ups.html, (24) volumes_editpartitions.html, or (25) volumes_iscsi_targets.html in admin/.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-3876

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Frams' Fast File EXchange (F*EX, aka fex) before fex-20140530 allow remote attackers to inject arbitrary web script or HTML via the (1) akey parameter to rup or (2) disclaimer or (3) gm parameter to fuc.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-4301

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-4302

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in rating/rating.php in HAM3D Shop Engine allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

    Published: 18 Jun 2014
    5
    Medium

    CVE-2014-0477

    Last Modified: 12 Apr 2025

    The parse function in Email::Address module before 1.905 for Perl uses an inefficient regular expression, which allows remote attackers to cause a denial of service (CPU consumption) via an empty quoted string in an RFC 2822 address.

    Published: 18 Jun 2014
    7.5
    High

    CVE-2014-0007

    Last Modified: 12 Apr 2025

    The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_boot_file.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-3491

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification boxes.

    Published: 18 Jun 2014
    1.9
    Low

    CVE-2014-4652

    Last Modified: 12 Apr 2025

    Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access.

    Published: 18 Jun 2014
    4.6
    Medium

    CVE-2014-4656

    Last Modified: 12 Apr 2025

    Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (1) index values in the snd_ctl_add function and (2) numid values in the snd_ctl_remove_numid_conflict function.

    Published: 18 Jun 2014
    4.3
    Medium

    CVE-2014-3492

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote attackers to inject arbitrary web script or HTML via a parameter (1) name or (2) value related to the host.

    Published: 18 Jun 2014
    4.6
    Medium

    CVE-2014-4653

    Last Modified: 12 Apr 2025

    sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access.

    Published: 18 Jun 2014
    4.6
    Medium

    CVE-2014-4654

    Last Modified: 12 Apr 2025

    The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and cause a denial of service (use-after-free and system crash) by leveraging /dev/snd/controlCX access for an ioctl call.

    Published: 18 Jun 2014
    4.9
    Medium

    CVE-2014-4655

    Last Modified: 12 Apr 2025

    The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial of service (integer overflow and limit bypass) by leveraging /dev/snd/controlCX access for a large number of SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl calls.

    Published: 18 Jun 2014
    5.8
    Medium

    CVE-2013-6078

    Last Modified: 12 Apr 2025

    The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging unspecified "security concerns," aka the ESA-2013-068 issue. NOTE: this issue has been SPLIT from CVE-2007-6755 because the vendor announcement did not state a specific technical rationale for a change in the algorithm; thus, CVE cannot reach a conclusion that a CVE-2007-6755 concern was the reason, or one of the reasons, for this change.

    Published: 17 Jun 2014
    5
    Medium

    CVE-2014-4191

    Last Modified: 12 Apr 2025

    The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) sends a long series of random bytes during use of the Dual_EC_DRBG algorithm, which makes it easier for remote attackers to obtain plaintext from TLS sessions by recovering the algorithm's inner state, a different issue than CVE-2007-6755.

    Published: 17 Jun 2014
    5
    Medium

    CVE-2014-4192

    Last Modified: 12 Apr 2025

    The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only the requested byte count and not the use of cached bytes, which makes it easier for remote attackers to obtain plaintext from TLS sessions by recovering the algorithm's inner state, a different issue than CVE-2007-6755.

    Published: 17 Jun 2014
    5
    Medium

    CVE-2014-4193

    Last Modified: 12 Apr 2025

    The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algorithm, which makes it easier for remote attackers to obtain plaintext from TLS sessions by requesting long nonces from a server, a different issue than CVE-2007-6755.

    Published: 17 Jun 2014
    5
    Medium

    CVE-2014-4047

    Last Modified: 12 Apr 2025

    Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 before 1.8.15-cert6 and 11.6 before 11.6-cert3 allows remote attackers to cause a denial of service (connection consumption) via a large number of (1) inactive or (2) incomplete HTTP connections.

    Published: 17 Jun 2014
    6.8
    Medium

    CVE-2014-4188

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Performance Management - Manager Web Option 07-00 through 07-54 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 17 Jun 2014
    6.5
    Medium

    CVE-2014-4046

    Last Modified: 12 Apr 2025

    Asterisk Open Source 11.x before 11.10.1 and 12.x before 12.3.1 and Certified Asterisk 11.6 before 11.6-cert3 allows remote authenticated Manager users to execute arbitrary shell commands via a MixMonitor action.

    Published: 17 Jun 2014
    4
    Medium

    CVE-2014-0478

    Last Modified: 12 Apr 2025

    APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.

    Published: 17 Jun 2014
    5
    Medium

    CVE-2014-3249

    Last Modified: 12 Apr 2025

    Puppet Enterprise 2.8.x before 2.8.7 allows remote attackers to obtain sensitive information via vectors involving hiding and unhiding nodes.

    Published: 17 Jun 2014
    4.3
    Medium

    CVE-2014-4048

    Last Modified: 12 Apr 2025

    The PJSIP Channel Driver in Asterisk Open Source before 12.3.1 allows remote attackers to cause a denial of service (deadlock) by terminating a subscription request before it is complete, which triggers a SIP transaction timeout.

    Published: 17 Jun 2014
    4.3
    Medium

    CVE-2014-4189

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Hitachi Tuning Manager before 7.6.1-06 and 8.x before 8.0.0-04 and JP1/Performance Management - Manager Web Option 07-00 through 07-54 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Jun 2014
    7.8
    High

    CVE-2014-4190

    Last Modified: 12 Apr 2025

    Multiple heap-based buffer overflows in Huawei Campus Series Switches S3700HI, S5700, S6700, S3300HI, S5300, S6300, S9300, S7700, and LSW S9700 with software V200R001 before V200R001SPH013; S5700, S6700, S5300, and S6300 with software V200R002 before V200R002SPH005; S7700, S9300, S9300E, S5300, S5700, S6300, S6700, S2350, S2750, and LSW S9700 with software V200R003 before V200R003SPH005; and S7700, S9300, S9300E, and LSW S9700 with software V200R005 before V200R005C00SPC300 allow remote attackers to cause a denial of service (device restart) via a crafted length field in a packet.

    Published: 17 Jun 2014
    5
    Medium

    CVE-2014-4044

    Last Modified: 12 Apr 2025

    OpenAFS 1.6.8 does not properly clear the fields in the host structure, which allows remote attackers to cause a denial of service (uninitialized memory access and crash) via unspecified vectors related to TMAY requests.

    Published: 17 Jun 2014
    4.3
    Medium

    CVE-2014-4045

    Last Modified: 12 Apr 2025

    The Publish/Subscribe Framework in the PJSIP channel driver in Asterisk Open Source 12.x before 12.3.1, when sub_min_expiry is set to zero, allows remote attackers to cause a denial of service (assertion failure and crash) via an unsubscribe request when not subscribed to the device.

    Published: 17 Jun 2014
    4.3
    Medium

    CVE-2014-4187

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in signup.php in ClipBucket allows remote attackers to inject arbitrary web script or HTML via the Username field.

    Published: 17 Jun 2014
    2.7
    Low

    CVE-2014-4021

    Last Modified: 12 Apr 2025

    Xen 3.2.x through 4.4.x does not properly clean memory pages recovered from guests, which allows local guest OS users to obtain sensitive information via unspecified vectors.

    Published: 17 Jun 2014
    4.7
    Medium

    CVE-2014-4171

    Last Modified: 12 Apr 2025

    mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.

    Published: 17 Jun 2014
    9.8
    Critical

    CVE-2014-5044

    Last Modified: 21 Nov 2024

    Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of service (Fortran application crash) via vectors related to array allocation.

    Published: 17 Jun 2014
    4.3
    Medium

    CVE-2014-3494

    Last Modified: 12 Apr 2025

    kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.

    Published: 17 Jun 2014
    10
    Critical

    CVE-2014-3496

    Last Modified: 12 Apr 2025

    cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz, or (4) .tar file extension in a cartridge manifest file.

    Published: 17 Jun 2014
    5
    Medium

    CVE-2014-5165

    Last Modified: 12 Apr 2025

    The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not properly validate padding values, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet.

    Published: 17 Jun 2014
    6.9
    Medium

    CVE-2014-8583

    Last Modified: 12 Apr 2025

    mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors.

    Published: 17 Jun 2014
    Unknown

    CVE-2013-7072

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a unique security issue, and some vulnerability databases had associated inapplicable details with this ID. Notes: none

    Published: 16 Jun 2014
    4.3
    Medium

    CVE-2014-3995

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in gravatars/templatetags/gravatars.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django allows remote attackers to inject arbitrary web script or HTML via a user display name.

    Published: 16 Jun 2014
    4.3
    Medium

    CVE-2014-3428

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary web script or HTML via the model parameter to servlet.

    Published: 16 Jun 2014
    6.8
    Medium

    CVE-2010-5111

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in readline.c in Echoping 6.0.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted reply in the (1) TLS_readline or (2) SSL_readline function, related to the EchoPingHttps Smokeping probe.

    Published: 16 Jun 2014
    4.3
    Medium

    CVE-2014-3994

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in util/templatetags/djblets_js.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django, as used in Review Board, allows remote attackers to inject arbitrary web script or HTML via a JSON object, as demonstrated by the name field when changing a user name.

    Published: 16 Jun 2014
    6.8
    Medium

    CVE-2014-4162

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Zyxel P-660HW-T1 (v3) wireless router allow remote attackers to hijack the authentication of administrators for requests that change the (1) wifi password or (2) SSID via a request to Forms/WLAN_General_1.

    Published: 16 Jun 2014
    4.3
    Medium

    CVE-2014-4166

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the song history in SHOUTcast DNAS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the mp3 title field.

    Published: 16 Jun 2014
    4.3
    Medium

    CVE-2014-4165

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a list action to plugins/rrdPlugin.

    Published: 16 Jun 2014
    6.8
    Medium

    CVE-2014-4163

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Featured Comments plugin 1.2.1 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change the (1) buried or (2) featured status of a comment via a request to wp-admin/admin-ajax.php.

    Published: 16 Jun 2014
    4.3
    Medium

    CVE-2014-4164

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in AlgoSec FireFlow 6.3-b230 allows remote attackers to inject arbitrary web script or HTML via a user signature to SelfService/Prefs.html.

    Published: 16 Jun 2014
    7.6
    High

    CVE-2014-2003

    Last Modified: 12 Apr 2025

    JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature.

    Published: 16 Jun 2014
    5
    Medium

    CVE-2014-2004

    Last Modified: 12 Apr 2025

    The PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 routers 1.00 through 3.10, SEIL/X1 routers 1.00 through 4.50, SEIL/X2 routers 1.00 through 4.50, SEIL/B1 routers 1.00 through 4.50, SEIL/Turbo routers 1.80 through 2.17, and SEIL/neu 2FE Plus routers 1.80 through 2.17 allows remote attackers to cause a denial of service (session termination or concentrator outage) via a crafted TCP packet.

    Published: 16 Jun 2014
    4.7
    Medium

    CVE-2014-4508

    Last Modified: 12 Apr 2025

    arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of service (OOPS and system crash) via an invalid syscall number, as demonstrated by number 1000.

    Published: 16 Jun 2014
    4.3
    Medium

    CVE-2014-2002

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in C-BOARD Moyuku 1.01b6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Jun 2014
    4.8
    Medium

    CVE-2014-3290

    Last Modified: 12 Apr 2025

    The mDNS implementation in Cisco IOS XE 3.12S does not properly interact with autonomic networking, which allows remote attackers to obtain sensitive networking-services information by sniffing the network or overwrite networking-services data via a crafted mDNS response, aka Bug ID CSCun64867.

    Published: 14 Jun 2014