CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2014-3836

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud Server before 6.0.3 allow remote attackers to hijack the authentication of users for requests that (1) conduct cross-site scripting (XSS) attacks, (2) modify files, or (3) rename files via unspecified vectors.

    Published: 4 Jun 2014
    4
    Medium

    CVE-2014-3837

    Last Modified: 12 Apr 2025

    The document application in ownCloud Server before 6.0.3 uses sequential values for the file_id, which allows remote authenticated users to enumerate shared files via unspecified vectors.

    Published: 4 Jun 2014
    10
    Critical

    CVE-2014-3913

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrary code via a request for a non-existent file.

    Published: 4 Jun 2014
    7.5
    High

    CVE-2014-3962

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Videos Tube 1.0 allow remote attackers to execute arbitrary SQL commands via the url parameter to (1) videocat.php or (2) single.php.

    Published: 4 Jun 2014
    4
    Medium

    CVE-2014-3963

    Last Modified: 12 Apr 2025

    ownCloud Server before 6.0.1 does not properly check permissions, which allows remote authenticated users to access arbitrary preview pictures via unspecified vectors.

    Published: 4 Jun 2014
    4.3
    Medium

    CVE-2012-5057

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in ownCloud Server before 4.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the url path parameter.

    Published: 4 Jun 2014
    4
    Medium

    CVE-2012-5336

    Last Modified: 12 Apr 2025

    lib/base.php in ownCloud before 4.0.8 does not properly validate the user_id session variable, which allows remote authenticated users to read arbitrary files via vectors related to WebDAV.

    Published: 4 Jun 2014
    4.6
    Medium

    CVE-2014-0935

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in IBM Smart Analytics System 7700 before FP 2.1.3.0 and 7710 before FP 2.1.3.0 allows local users to gain privileges via vectors related to events.

    Published: 4 Jun 2014
    4.3
    Medium

    CVE-2014-2502

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in rsa_fso.swf in EMC RSA Adaptive Authentication (Hosted) 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Jun 2014
    7.8
    High

    CVE-2014-3153

    Last Modified: 21 Apr 2026

    The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.

    Published: 4 Jun 2014
    3.3
    Low

    CVE-2014-3981

    Last Modified: 12 Apr 2025

    acinclude.m4, as used in the configure script in PHP 5.5.13 and earlier, allows local users to overwrite arbitrary files via a symlink attack on the /tmp/phpglibccheck file.

    Published: 4 Jun 2014
    4
    Medium

    CVE-2014-3945

    Last Modified: 12 Apr 2025

    The Authentication component in TYPO3 before 6.2, when salting for password hashing is disabled, does not require knowledge of the cleartext password if the password hash is known, which allows remote attackers to bypass authentication and gain access to the backend by leveraging knowledge of a password hash.

    Published: 3 Jun 2014
    5
    Medium

    CVE-2013-0191

    Last Modified: 12 Apr 2025

    libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass authentication via a crafted password.

    Published: 3 Jun 2014
    5
    Medium

    CVE-2014-3941

    Last Modified: 12 Apr 2025

    TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allows remote attackers to have unspecified impact via a crafted HTTP Host header, related to "Host Spoofing."

    Published: 3 Jun 2014
    6
    Medium

    CVE-2014-3942

    Last Modified: 12 Apr 2025

    The Color Picker Wizard component in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, and 6.1.0 before 6.1.9 allows remote authenticated editors to execute arbitrary PHP code via a serialized PHP object.

    Published: 3 Jun 2014
    4.3
    Medium

    CVE-2014-3959

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in list.jsp in the Configuration utility in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, GTM, and Link Controller 11.2.1 through 11.5.1, AAM 11.4.0 through 11.5.1 PEM 11.3.0 through 11.5.1, PSM 11.2.1 through 11.4.1, WebAccelerator and WOM 11.2.1 through 11.3.0, and Enterprise Manager 3.0.0 through 3.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 3 Jun 2014
    3.5
    Low

    CVE-2014-3943

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in unspecified backend components in TYPO3 4.5.0 before 4.5.34, 4.7.0 before 4.7.19, 6.0.0 before 6.0.14, 6.1.0 before 6.1.9, and 6.2.0 before 6.2.3 allow remote authenticated editors to inject arbitrary web script or HTML via unknown parameters.

    Published: 3 Jun 2014
    5.8
    Medium

    CVE-2014-3944

    Last Modified: 12 Apr 2025

    The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypass authentication via unspecified vectors.

    Published: 3 Jun 2014
    4
    Medium

    CVE-2014-3946

    Last Modified: 12 Apr 2025

    The query caching functionality in the Extbase Framework component in TYPO3 6.2.0 before 6.2.3 does not properly validate group permissions, which allows remote authenticated users to read arbitrary queries via unspecified vectors.

    Published: 3 Jun 2014
    4
    Medium

    CVE-2014-3280

    Last Modified: 12 Apr 2025

    The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user information by visiting an unspecified Administration GUI web page, aka Bug IDs CSCun46045 and CSCun46116.

    Published: 3 Jun 2014
    5.5
    Medium

    CVE-2014-3967

    Last Modified: 12 Apr 2025

    The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors.

    Published: 3 Jun 2014
    5.5
    Medium

    CVE-2014-3968

    Last Modified: 12 Apr 2025

    The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a large number of crafted requests, which trigger an error messages to be logged.

    Published: 3 Jun 2014
    4.3
    Medium

    CVE-2014-2939

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Alfresco Enterprise before 4.1.6.13 allow remote attackers to inject arbitrary web script or HTML via (1) an XHTML document, (2) a <% tag, or (3) the taskId parameter to share/page/task-edit.

    Published: 2 Jun 2014
    6.8
    Medium

    CVE-2014-2946

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in api/sms/send-sms in the Web UI 11.010.06.01.858 on Huawei E303 modems with software 22.157.18.00.858 allows remote attackers to hijack the authentication of administrators for requests that perform API operations and send SMS messages via a request element in an XML document.

    Published: 2 Jun 2014
    9
    Critical

    CVE-2014-2959

    Last Modified: 12 Apr 2025

    logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter.

    Published: 2 Jun 2014
    9.3
    Critical

    CVE-2013-2019

    Last Modified: 8 Jul 2025

    Stack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote attackers to have unspecified impact via multiple file_signature elements.

    Published: 2 Jun 2014
    5.8
    Medium

    CVE-2013-4596

    Last Modified: 12 Apr 2025

    The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote attackers to bypass access restrictions via a node listing.

    Published: 2 Jun 2014
    6.8
    Medium

    CVE-2013-7387

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie.

    Published: 2 Jun 2014
    5
    Medium

    CVE-2013-1818

    Last Modified: 12 Apr 2025

    maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 2 Jun 2014
    5
    Medium

    CVE-2011-5280

    Last Modified: 8 Jul 2025

    Multiple stack-based buffer overflows in BOINC 6.13.x allow remote attackers to cause a denial of service (crash) via a long trickle-up to (1) client/cs_trickle.cpp or (2) db/db_base.cpp.

    Published: 2 Jun 2014
    6.8
    Medium

    CVE-2012-5391

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in Special:UserLogin in MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the session_id.

    Published: 2 Jun 2014
    6.8
    Medium

    CVE-2012-5395

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in the CentralAuth extension for MediaWiki before 1.18.6, 1.19.x before 1.19.3, and 1.20.x before 1.20.1 allows remote attackers to hijack web sessions via the centralauth_Session cookie.

    Published: 2 Jun 2014
    7.5
    High

    CVE-2013-1348

    Last Modified: 12 Apr 2025

    The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.

    Published: 2 Jun 2014
    7.5
    High

    CVE-2013-1397

    Last Modified: 12 Apr 2025

    Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348.

    Published: 2 Jun 2014
    7.5
    High

    CVE-2013-1412

    Last Modified: 12 Apr 2025

    DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.

    Published: 2 Jun 2014
    9.3
    Critical

    CVE-2013-2298

    Last Modified: 8 Jul 2025

    Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a crafted XML file, related to the scheduler.

    Published: 2 Jun 2014
    6.8
    Medium

    CVE-2013-2710

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 2 Jun 2014
    6.8
    Medium

    CVE-2013-3257

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via unspecified vectors.

    Published: 2 Jun 2014
    6.8
    Medium

    CVE-2013-3476

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows remote attackers to hijack the authentication of users for requests that change settings via unspecified vectors.

    Published: 2 Jun 2014
    5
    Medium

    CVE-2013-7386

    Last Modified: 8 Jul 2025

    Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the gui_urls item in an account file.

    Published: 2 Jun 2014
    6.8
    Medium

    CVE-2013-3258

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via unspecified vectors.

    Published: 2 Jun 2014
    7.5
    High

    CVE-2014-3937

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Contextual Related Posts plugin before 1.8.10.2 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 2 Jun 2014
    7.5
    High

    CVE-2014-3932

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the device registration component in wsf/webservice.php in CoSoSys Endpoint Protector 4 4.3.0.4 and 4.4.0.2 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

    Published: 2 Jun 2014
    3.5
    Low

    CVE-2014-3933

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the address components field formatter in the AddressField Tokens module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via an address field.

    Published: 2 Jun 2014
    10
    Critical

    CVE-2014-3936

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06 and earlier, DIR-505 with firmware before 1.08b10, and DIR-505L with firmware 1.01 and earlier allows remote attackers to execute arbitrary code via a long Content-Length header in a GetDeviceSettings action in an HNAP request.

    Published: 2 Jun 2014
    7.5
    High

    CVE-2014-3934

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL commands via the topics[] parameter to modules.php.

    Published: 2 Jun 2014
    7.5
    High

    CVE-2014-3935

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execute arbitrary SQL commands via the lettre parameter.

    Published: 2 Jun 2014
    9
    Critical

    CVE-2014-3790

    Last Modified: 12 Apr 2025

    Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping from a chroot jail.

    Published: 1 Jun 2014
    5.8
    Medium

    CVE-2014-3793

    Last Modified: 12 Apr 2025

    VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain guest OS privileges or cause a denial of service (kernel NULL pointer dereference and guest OS crash) via unspecified vectors.

    Published: 31 May 2014
    2.9
    Low

    CVE-2014-3970

    Last Modified: 12 Apr 2025

    The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure and abort) via an empty UDP packet.

    Published: 31 May 2014