CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2013-2602

    Last Modified: 12 Apr 2025

    Multiple array index errors in the MyHeritage SEQueryObject ActiveX control (SearchEngineQuery.dll) 1.0.2.0 allow remote attackers to execute arbitrary code via the (1) seTokensArray, or (2) seTokensValuesArray parameter to the AddTokens method; (3) seLastNameTokensArray parameter to the AddLastNameTokens method; (4) seFrameIdArray, (5) seSourceIdArray, (6) seHasBreakdownArray, (7) seIsIndexedArray, (8) seAllConcatArray, (9) seRefererURLArray, or (10) seMandatoryFieldsArray parameter to the AddMultipleSearches method; (11) seSourceIdArray, (12) seIsIndexedArray, (13) seAllConcatArray, (14) seRefererURLArray, (15) seQATestsArray, (16) seAllSourceIDsArray, (17) seAllSourceTitlesArray, (18) seMandatoryFieldsArray, or (19) seAllSourceRootURLArray parameter to the TestYourself method.

    Published: 6 Jun 2014
    6.5
    Medium

    CVE-2014-2575

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.

    Published: 6 Jun 2014
    7.5
    High

    CVE-2014-2503

    Last Modified: 12 Apr 2025

    The thumbnail proxy server in EMC Documentum Digital Asset Manager (DAM) 6.5 SP3, 6.5 SP4, 6.5 SP5, and 6.5 SP6 before P13 allows remote attackers to conduct Documentum Query Language (DQL) injection attacks and bypass intended restrictions on querying objects via a crafted parameter in a query string.

    Published: 6 Jun 2014
    8.3
    High

    CVE-2013-4860

    Last Modified: 12 Apr 2025

    Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the operation mode, wifi connection settings, temperature thresholds, and other settings via unspecified vectors.

    Published: 5 Jun 2014
    9.3
    Critical

    CVE-2013-0733

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jpg file.

    Published: 5 Jun 2014
    4
    Medium

    CVE-2013-2130

    Last Modified: 12 Apr 2025

    ZNC 1.0 allows remote authenticated users to cause a denial of service (NULL pointer reference and crash) via a crafted request to the (1) editnetwork, (2) editchan, (3) addchan, or (4) delchan page in modules/webadmin.cpp.

    Published: 5 Jun 2014
    4.3
    Medium

    CVE-2013-2618

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HTML via the map_title parameter.

    Published: 5 Jun 2014
    5
    Medium

    CVE-2013-3739

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the mapname parameter in a show_config action.

    Published: 5 Jun 2014
    7.4
    High

    CVE-2014-3969

    Last Modified: 12 Apr 2025

    Xen 4.4.x, when running on an ARM system, does not properly check write permissions on virtual addresses, which allows local guest administrators to gain privileges via unspecified vectors.

    Published: 5 Jun 2014
    4.3
    Medium

    CVE-2012-4728

    Last Modified: 12 Apr 2025

    The (1) QProGetNotebookWindowHandle and (2) Ordinal132 functions in QPW160.dll in Corel Quattro Pro X6 Standard Edition 16.0.0.388 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted QPW file.

    Published: 5 Jun 2014
    4.3
    Medium

    CVE-2014-3878

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact action in the Contacts section or unspecified vectors in (2) an Add Group task in the Contacts section, (3) an add new event action in the Calendar section, or (4) the Task section.

    Published: 5 Jun 2014
    7.8
    High

    CVE-2014-1997

    Last Modified: 12 Apr 2025

    The ATEN CN8000 remote-access unit with firmware 1.6.154 and earlier allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 5 Jun 2014
    4.3
    Medium

    CVE-2014-1998

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Nippon Institute of Agroinformatics SOY CMS 1.4.0c and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jun 2014
    4.3
    Medium

    CVE-2014-2577

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Transform Content Center in Bottomline Technologies Transform Foundation Server before 4.3.1 Patch 8 and 5.x before 5.2 Patch 7 allow remote attackers to inject arbitrary web script or HTML via the (1) pn parameter to index.fsp/document.pdf, (2) db or (3) referer parameter to index.fsp/index.fsp, or (4) PATH_INFO to the default URI.

    Published: 5 Jun 2014
    9.3
    Critical

    CVE-2014-3912

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the FindConfigChildeKeyList method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control in Samsung iPOLiS Device Manager before 1.8.7 allows remote attackers to execute arbitrary code via a long value.

    Published: 5 Jun 2014
    7.5
    High

    CVE-2014-3973

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.3.21 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 5 Jun 2014
    5
    Medium

    CVE-2014-3976

    Last Modified: 12 Apr 2025

    Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long session id in the URI to sys_reboot.html. NOTE: some of these details are obtained from third party information.

    Published: 5 Jun 2014
    4.3
    Medium

    CVE-2014-3974

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the viewdir parameter.

    Published: 5 Jun 2014
    5
    Medium

    CVE-2014-3975

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via a full pathname in the viewdir parameter.

    Published: 5 Jun 2014
    7.1
    High

    CVE-2014-2345

    Last Modified: 2 Oct 2025

    COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow remote attackers to cause a denial of service (infinite loop and process crash) by sending a crafted DNP3 packet over TCP.

    Published: 5 Jun 2014
    4
    Medium

    CVE-2014-2346

    Last Modified: 2 Oct 2025

    COPA-DATA zenon DNP3 NG driver (DNP3 master) 7.10 and 7.11 through 7.11 SP0 build 10238 and zenon DNP3 Process Gateway (DNP3 outstation) 7.11 SP0 build 10238 and earlier allow physically proximate attackers to cause a denial of service (infinite loop and process crash) via crafted input over a serial line.

    Published: 5 Jun 2014
    4
    Medium

    CVE-2013-0304

    Last Modified: 12 Apr 2025

    ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. NOTE: this issue has been reported as a cross-site request forgery (CSRF) vulnerability, but due to lack of details, it is uncertain what the root cause is.

    Published: 5 Jun 2014
    7.5
    High

    CVE-2014-2051

    Last Modified: 12 Apr 2025

    ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to conduct an LDAP injection attack via unspecified vectors, as demonstrated using a "login query."

    Published: 5 Jun 2014
    5
    Medium

    CVE-2013-0302

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in ownCloud Server before 4.0.12 allows remote attackers to obtain sensitive information via unspecified vectors related to "inclusion of the Amazon SDK testing suite." NOTE: due to lack of details, it is not clear whether the issue exists in ownCloud itself, or in Amazon SDK.

    Published: 5 Jun 2014
    5
    Medium

    CVE-2014-9449

    Last Modified: 12 Apr 2025

    Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cause a denial of service (crash) via a long IKEY INFO tag value in an AVI file.

    Published: 5 Jun 2014
    6.8
    Medium

    CVE-2014-0195

    Last Modified: 12 Apr 2025

    The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

    Published: 5 Jun 2014
    4.3
    Medium

    CVE-2014-0221

    Last Modified: 12 Apr 2025

    The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.

    Published: 5 Jun 2014
    7.4
    High

    CVE-2014-0224

    Last Modified: 12 Apr 2025

    OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

    Published: 5 Jun 2014
    4.3
    Medium

    CVE-2014-3470

    Last Modified: 12 Apr 2025

    The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.

    Published: 5 Jun 2014
    5
    Medium

    CVE-2014-3481

    Last Modified: 12 Apr 2025

    org.jboss.as.jaxrs.deployment.JaxrsIntegrationProcessor in Red Hat JBoss Enterprise Application Platform (JEAP) before 6.2.4 enables entity expansion, which allows remote attackers to read arbitrary files via unspecified vectors, related to an XML External Entity (XXE) issue.

    Published: 5 Jun 2014
    7.5
    High

    CVE-2012-6141

    Last Modified: 12 Apr 2025

    The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request to (1) App::Session::Cookie or (2) App::Session::HTMLHidden, which is not properly handled when it is deserialized.

    Published: 4 Jun 2014
    7.5
    High

    CVE-2012-6143

    Last Modified: 12 Apr 2025

    Spoon::Cookie in the Spoon module 0.24 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.

    Published: 4 Jun 2014
    7.5
    High

    CVE-2012-6142

    Last Modified: 12 Apr 2025

    Session::Cookie in the HTML::EP module 0.2011 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.

    Published: 4 Jun 2014
    7.5
    High

    CVE-2014-2053

    Last Modified: 12 Apr 2025

    getID3() before 1.9.8, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

    Published: 4 Jun 2014
    3.5
    Low

    CVE-2014-3949

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the layout wizard in the Grid Elements (gridelements) extension before 1.5.1 and 2.0.x before 2.0.3 for TYPO3 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Jun 2014
    4.6
    Medium

    CVE-2013-0204

    Last Modified: 12 Apr 2025

    settings/personal.php in ownCloud 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via crafted mount point settings.

    Published: 4 Jun 2014
    5
    Medium

    CVE-2013-1941

    Last Modified: 12 Apr 2025

    The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time function to seed the generation of the PostgreSQL database user password, which makes it easier for remote attackers to guess the password via a brute force attack.

    Published: 4 Jun 2014
    7.5
    High

    CVE-2014-2054

    Last Modified: 12 Apr 2025

    PHPExcel before 1.8.0, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, does not disable external entity loading in libxml, which allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

    Published: 4 Jun 2014
    4.3
    Medium

    CVE-2012-5056

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 4.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) readyCallback parameter to apps/files_odfviewer/src/webodf/webodf/flashput/PUT.swf, the (2) root parameter to apps/gallery/templates/index.php, or a (3) malformed query to lib/db.php.

    Published: 4 Jun 2014
    4
    Medium

    CVE-2014-3838

    Last Modified: 12 Apr 2025

    ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not properly check permissions, which allows remote authenticated users to read the names of files of other users by leveraging access to multiple accounts.

    Published: 4 Jun 2014
    4.3
    Medium

    CVE-2014-3948

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the HTML export wizard in the backend module in the powermail extension before 1.6.11 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Jun 2014
    7.5
    High

    CVE-2014-2055

    Last Modified: 12 Apr 2025

    SabreDAV before 1.7.11, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

    Published: 4 Jun 2014
    7.5
    High

    CVE-2014-2056

    Last Modified: 12 Apr 2025

    PHPDocX, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML External Entity (XXE) attack.

    Published: 4 Jun 2014
    4.3
    Medium

    CVE-2014-3960

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.12.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Jun 2014
    7.5
    High

    CVE-2014-3961

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the query parameter in an "output CSV" action to pdb-signup/.

    Published: 4 Jun 2014
    4.3
    Medium

    CVE-2014-3786

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the contact module (admin/modules/contact.php) in Pixie CMS 1.04 allow remote attackers to inject arbitrary web script or HTML via the (1) uemail or (2) subject parameter in the Contact form to contact/.

    Published: 4 Jun 2014
    4.3
    Medium

    CVE-2014-3832

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Documents component in ownCloud Server 6.0.x before 6.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the print_unescaped function.

    Published: 4 Jun 2014
    4.3
    Medium

    CVE-2014-3833

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) Gallery and (2) core components in ownCloud Server before 5.016 and 6.0.x before 6.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the print_unescaped function.

    Published: 4 Jun 2014
    7.5
    High

    CVE-2014-3834

    Last Modified: 12 Apr 2025

    ownCloud Server before 6.0.3 does not properly check permissions, which allows remote authenticated users to (1) access the contacts of other users via the address book or (2) rename files via unspecified vectors.

    Published: 4 Jun 2014
    5.5
    Medium

    CVE-2014-3835

    Last Modified: 12 Apr 2025

    ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not check permissions to the files_external application, which allows remote authenticated users to add external storage via unspecified vectors.

    Published: 4 Jun 2014