CVE Feed

    Dashboard / CVE

    6.6
    Medium

    CVE-2014-0960

    Last Modified: 12 Apr 2025

    IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictions by establishing an SSH session from a deployed virtual machine.

    Published: 14 Jun 2014
    7.1
    High

    CVE-2014-2176

    Last Modified: 12 Apr 2025

    Cisco IOS XR 4.1.2 through 5.1.1 on ASR 9000 devices, when a Trident-based line card is used, allows remote attackers to cause a denial of service (NP chip and line card reload) via malformed IPv6 packets, aka Bug ID CSCun71928.

    Published: 14 Jun 2014
    4.8
    Medium

    CVE-2014-3295

    Last Modified: 12 Apr 2025

    The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309.

    Published: 14 Jun 2014
    6.8
    Medium

    CVE-2013-3843

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP header.

    Published: 13 Jun 2014
    6.8
    Medium

    CVE-2013-5352

    Last Modified: 12 Apr 2025

    Sharetronix 3.1.1.3, 3.1.1, and earlier allows remote attackers to execute arbitrary PHP code via the (1) activities_text parameter to services/activities/set or (2) comments_text parameter to services/comments/set, which is not properly handled when executing the preg_replace function with the e modifier.

    Published: 13 Jun 2014
    10
    Critical

    CVE-2014-3804

    Last Modified: 12 Apr 2025

    The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4) sync_rserver, or (5) set_ossim_setup framework_ip request, a different vulnerability than CVE-2014-3805.

    Published: 13 Jun 2014
    7.5
    High

    CVE-2010-5301

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a HEAD request.

    Published: 13 Jun 2014
    7.5
    High

    CVE-2014-2303

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the file browser component (we_fs.php) in webEdition CMS before 6.2.7-s1.2 and 6.3.x through 6.3.8 before -s1 allow remote attackers to execute arbitrary SQL commands via the (1) table or (2) order parameter.

    Published: 13 Jun 2014
    5
    Medium

    CVE-2012-3521

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in the cssgen contrib module in GeSHi before 1.0.8.11 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) geshi-path or (2) geshi-lang-path parameter.

    Published: 13 Jun 2014
    4.3
    Medium

    CVE-2012-3522

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in contrib/langwiz.php in GeSHi before 1.0.8.11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Jun 2014
    5.8
    Medium

    CVE-2013-2182

    Last Modified: 12 Apr 2025

    The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as demonstrated by an encoded forward slash.

    Published: 13 Jun 2014
    9.3
    Critical

    CVE-2013-3663

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 8 Maintenance 3, allows remote attackers to execute arbitrary code via a crafted RLE8 compressed BMP.

    Published: 13 Jun 2014
    6.8
    Medium

    CVE-2013-5353

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in system/controllers/ajax/attachments.php in Sharetronix 3.1.1.3, 3.1.1, and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

    Published: 13 Jun 2014
    7.5
    High

    CVE-2013-5356

    Last Modified: 12 Apr 2025

    Sharetronix 3.1.1.3, 3.1.1, and earlier does not properly restrict access to unspecified AJAX functionality, which allows remote attackers to bypass authentication via unknown vectors.

    Published: 13 Jun 2014
    4.3
    Medium

    CVE-2013-1841

    Last Modified: 12 Apr 2025

    Net-Server, when the reverse-lookups option is enabled, does not check if the hostname resolves to the source IP address, which might allow remote attackers to bypass ACL restrictions via the hostname parameter.

    Published: 13 Jun 2014
    5
    Medium

    CVE-2013-2163

    Last Modified: 12 Apr 2025

    Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the file size in the Range HTTP header.

    Published: 13 Jun 2014
    10
    Critical

    CVE-2013-4099

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in OpenAL32.dll in JOAL 2.0-rc11, as used in JOGAMP, allow context-dependent attackers to execute arbitrary code via a crafted parameter to the (1) alAuxiliaryEffectSlotf1, (2) alBuffer3f1, (3) alBufferfv1, (4) alDeleteEffects1, (5) alEffectf1, (6) alEffectfv1, (7) alEffectiv1, (8) alEnable1, (9) alFilterfv1, (10) alFilteriv1, (11) alGenAuxiliaryEffectSlots1, (12) alGenEffects1, (13) alGenFilters1, (14) alGenSources1, (15) alGetAuxiliaryEffectSlotiv1, (16) alGetBuffer3f1, (17) alGetBuffer3i1, (18) alGetBufferf1, (19) alGetBufferiv1, (20) alGetDoublev1, (21) alGetEffectf1, (22) alGetEffectfv1, (23) alGetEffectiv1, (24) alGetEnumValue1, (25) alGetFilteri1, (26) alGetFilteriv1, (27) alGetFloat1, (28) alGetFloatv1, (29) alGetListener3f1, (30) alGetListener3i1, (31) alGetListenerf1, (32) alGetListeneri1, (33) alGetListeneriv1, (34) alGetProcAddress1, (35) alGetProcAddressStatic, (36) alGetSource3f1, (37) alGetSource3i1, (38) alGetSourcef1, (39) alGetSourcefv1, (40) alGetSourcei1, (41) alGetSourceiv1, (42) alGetString1java/lang/String;, (43) alIsAuxiliaryEffectSlot1, (44) alIsBuffer1, (45) alIsEffect1, (46) alIsExtensionPresent1, (47) alIsFilter1, (48) alListener3f1, (49) alListener3i1, (50) alListenerf1, (51) alListenerfv1, (52) alListeneri1, (53) alListeneriv1, (54) alSource3f1, (55) alSource3i1, (56) alSourcef1, (57) alSourcefv1, (58) alSourcei1, (59) alSourceiv1, (60) alSourcePause1, (61) alSourcePausev1, (62) alSourcePlay1, (63) alSourcePlayv1, (64) alSourceQueueBuffers1, (65) alSourceRewindv1, (66) alSourceStop1, (67) alSourceStopv1, (68) alSourceUnqueueBuffers1, or (69) alSpeedOfSound1 method in jogamp.openal.ALImpl.dispatch.

    Published: 13 Jun 2014
    10
    Critical

    CVE-2014-3805

    Last Modified: 12 Apr 2025

    The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804.

    Published: 13 Jun 2014
    5
    Medium

    CVE-2014-3812

    Last Modified: 12 Apr 2025

    The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service (UAC) before 4.4r5 and 5.x before 5.0r1 enable cipher suites with weak encryption algorithms, which make it easier for remote attackers to obtain sensitive information by sniffing the network.

    Published: 13 Jun 2014
    7.8
    High

    CVE-2014-3813

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Juniper Networks NetScreen Firewall products with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote attackers to cause a denial of service (crash and reboot) via vectors related to a DNS lookup.

    Published: 13 Jun 2014
    7.5
    High

    CVE-2014-4158

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET request.

    Published: 13 Jun 2014
    5.8
    Medium

    CVE-2014-4159

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

    Published: 13 Jun 2014
    7.8
    High

    CVE-2014-3814

    Last Modified: 12 Apr 2025

    The Juniper Networks NetScreen Firewall devices with ScreenOS before 6.3r17, when configured to use the internal DNS lookup client, allows remote attackers to cause a denial of service (crash and reboot) via a sequence of malformed packets to the device IP.

    Published: 13 Jun 2014
    4.3
    Medium

    CVE-2014-4160

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the testcanvas node in SAP NetWeaver Business Client (NWBC) allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) sap-accessibility parameter.

    Published: 13 Jun 2014
    4.3
    Medium

    CVE-2014-4161

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 13 Jun 2014
    4.4
    Medium

    CVE-2014-4038

    Last Modified: 12 Apr 2025

    ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_support.c and /tmp/get_dt_files, (2) scripts/ppc64_diag_mkrsrc and /tmp/diagSEsnap/snapH.tar.gz, or (3) lpd/test/lpd_ela_test.sh and /var/tmp/ras.

    Published: 13 Jun 2014
    2.1
    Low

    CVE-2014-4039

    Last Modified: 12 Apr 2025

    ppc64-diag 2.6.1 uses 0775 permissions for /tmp/diagSEsnap and does not properly restrict permissions for /tmp/diagSEsnap/snapH.tar.gz, which allows local users to obtain sensitive information by reading files in this archive, as demonstrated by /var/log/messages and /etc/yaboot.conf.

    Published: 13 Jun 2014
    5
    Medium

    CVE-2014-4040

    Last Modified: 12 Apr 2025

    snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

    Published: 13 Jun 2014
    3.3
    Low

    CVE-2014-0244

    Last Modified: 12 Apr 2025

    The sys_recvfrom function in nmbd in Samba 3.6.x before 3.6.24, 4.0.x before 4.0.19, and 4.1.x before 4.1.9 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed UDP packet.

    Published: 12 Jun 2014
    6
    Medium

    CVE-2014-3476

    Last Modified: 12 Apr 2025

    OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.

    Published: 12 Jun 2014
    5
    Medium

    CVE-2014-4667

    Last Modified: 12 Apr 2025

    The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.

    Published: 12 Jun 2014
    10
    Critical

    CVE-2014-2977

    Last Modified: 12 Apr 2025

    Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow.

    Published: 11 Jun 2014
    6.8
    Medium

    CVE-2014-3850

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Member Approval plugin 131109 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings to their default and disable registration approval via a request to wp-admin/options-general.php.

    Published: 11 Jun 2014
    4.3
    Medium

    CVE-2014-4037

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitrary web script or HTML via an array key in the textinputs[] parameter, a different issue than CVE-2012-4000.

    Published: 11 Jun 2014
    6.8
    Medium

    CVE-2010-5300

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name in a zip archive.

    Published: 11 Jun 2014
    9.3
    Critical

    CVE-2011-3625

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a SAMI subtitle file.

    Published: 11 Jun 2014
    10
    Critical

    CVE-2014-2978

    Last Modified: 12 Apr 2025

    The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write.

    Published: 11 Jun 2014
    9.3
    Critical

    CVE-2014-3911

    Last Modified: 12 Apr 2025

    Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeControlLocalName, (3) DeleteDeviceProfile, (4) FrameAdvanceReader, or other unknown method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control.

    Published: 11 Jun 2014
    4.6
    Medium

    CVE-2014-3980

    Last Modified: 12 Apr 2025

    libfep 0.0.5 before 0.1.0 does not properly use UNIX domain sockets in the abstract namespace, which allows local users to gain privileges via unspecified vectors.

    Published: 11 Jun 2014
    5.8
    Medium

    CVE-2014-3781

    Last Modified: 12 Apr 2025

    The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty password in an XML-RPC request.

    Published: 11 Jun 2014
    6
    Medium

    CVE-2014-3782

    Last Modified: 12 Apr 2025

    Multiple incomplete blacklist vulnerabilities in the filemanager::isFileExclude method in the Media Manager in Dotclear before 2.6.3 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) double extension or (2) .php5, (3) .phtml, or some other PHP file extension.

    Published: 11 Jun 2014
    10
    Critical

    CVE-2014-3915

    Last Modified: 12 Apr 2025

    The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands via a (1) auth, (2) auth_session, (3) auth_simple, (4) add, (5) add_flat, (6) remove, (7) set_pwd, (8) add_permissions, (9) revoke_permissions, (10) runAsync, or (11) tsmRequest command.

    Published: 11 Jun 2014
    4.3
    Medium

    CVE-2014-4032

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in apps/app_comment/form_comment.php in Fiyo CMS 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the Nama field.

    Published: 11 Jun 2014
    4.3
    Medium

    CVE-2014-4033

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via the surname parameter to student.php.

    Published: 11 Jun 2014
    7.5
    High

    CVE-2014-4034

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the article_id parameter.

    Published: 11 Jun 2014
    4.3
    Medium

    CVE-2014-4035

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Published: 11 Jun 2014
    4.3
    Medium

    CVE-2014-4036

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a listimg action.

    Published: 11 Jun 2014
    5
    Medium

    CVE-2014-1539

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 30.0 and Thunderbird through 24.6 on OS X do not ensure visibility of the cursor after interaction with a Flash object and a DIV element, which makes it easier for remote attackers to conduct clickjacking attacks via JavaScript code that produces a fake cursor image.

    Published: 11 Jun 2014
    7.5
    High

    CVE-2014-3154

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the ChildThread::Shutdown function in content/child/child_thread.cc in the filesystem API in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to a Blink shutdown.

    Published: 11 Jun 2014
    5
    Medium

    CVE-2014-3155

    Last Modified: 12 Apr 2025

    net/spdy/spdy_write_queue.cc in the SPDY implementation in Google Chrome before 35.0.1916.153 allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging incorrect queue maintenance.

    Published: 11 Jun 2014