CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2013-6744

    Last Modified: 12 Apr 2025

    The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated users to gain privileges by leveraging the CONNECT privilege and the CREATE_EXTERNAL_ROUTINE authority.

    Published: 30 May 2014
    7.2
    High

    CVE-2014-0907

    Last Modified: 12 Apr 2025

    Multiple untrusted search path vulnerabilities in unspecified (1) setuid and (2) setgid programs in IBM DB2 9.5, 9.7 before FP9a, 9.8, 10.1 before FP3a, and 10.5 before FP3a on Linux and UNIX allow local users to gain root privileges via a Trojan horse library.

    Published: 30 May 2014
    1.2
    Low

    CVE-2014-2343

    Last Modified: 2 Oct 2025

    Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of service (excessive data processing) via a crafted DNP request over a serial line.

    Published: 30 May 2014
    4.3
    Medium

    CVE-2014-2342

    Last Modified: 2 Oct 2025

    Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafted DNP3 packet.

    Published: 30 May 2014
    7.8
    High

    CVE-2014-2352

    Last Modified: 3 Oct 2025

    The directory specifier can include designators that can be used to traverse the directory path. Exploiting this vulnerability may enable an attacker to access a limited number of hardcoded file types. Further exploitation of this vulnerability may allow an attacker to cause the web server component to enter a denial-of-service condition.

    Published: 30 May 2014
    6
    Medium

    CVE-2014-2354

    Last Modified: 3 Oct 2025

    Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

    Published: 30 May 2014
    7.1
    High

    CVE-2014-2353

    Last Modified: 3 Oct 2025

    Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 May 2014
    3.5
    Low

    CVE-2014-0925

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in IBM Sterling Control Center 5.4.0 before 5.4.0.1 iFix 3 and 5.4.1 before 5.4.1.0 iFix 2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

    Published: 30 May 2014
    6.4
    Medium

    CVE-2014-3227

    Last Modified: 12 Apr 2025

    dpkg 1.15.9, 1.16.x before 1.16.14, and 1.17.x before 1.17.9 expect the patch program to be compliant with a need for the "C-style encoded filenames" feature, but is supported in environments with noncompliant patch programs, which triggers an interaction error that allows remote attackers to conduct directory traversal attacks and modify files outside of the intended directories via a crafted source package. NOTE: this vulnerability exists because of reliance on unrealistic constraints on the behavior of an external program.

    Published: 30 May 2014
    6.4
    Medium

    CVE-2014-3864

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in dpkg-source in dpkg-dev 1.3.0 allows remote attackers to modify files outside of the intended directories via a crafted source package that lacks a --- header line.

    Published: 30 May 2014
    6.4
    Medium

    CVE-2014-3865

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunction with (1) missing --- and +++ header lines or (2) a +++ header line with a blank pathname.

    Published: 30 May 2014
    4.3
    Medium

    CVE-2014-3010

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.2, 6.3 before 6.3.0.6, 7.0 before 7.0.0.6, 7.5 before 7.5.0.5, and 8.0 before 8.0.0.3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 30 May 2014
    7.5
    High

    CVE-2013-6788

    Last Modified: 12 Apr 2025

    The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for remote attackers to guess the cookie value and bypass authentication via a brute force attack.

    Published: 30 May 2014
    2.1
    Low

    CVE-2012-5560

    Last Modified: 12 Apr 2025

    The default configuration in mate-settings-daemon 1.5.3 allows local users to change the timezone for the system via a crafted D-Bus call.

    Published: 30 May 2014
    5
    Medium

    CVE-2012-5572

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the cookie method (lib/Dancer/Cookie.pm) in Dancer before 1.3114 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a cookie name, a different vulnerability than CVE-2012-5526.

    Published: 30 May 2014
    5
    Medium

    CVE-2012-5876

    Last Modified: 12 Apr 2025

    Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of service (crash) via a long string in the (1) request line or (2) HTTP Referer header to TCP port 54444, which triggers a heap-based buffer overflow.

    Published: 30 May 2014
    5
    Medium

    CVE-2012-5877

    Last Modified: 12 Apr 2025

    Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an HTTP header without a name.

    Published: 30 May 2014
    5
    Medium

    CVE-2013-5919

    Last Modified: 12 Apr 2025

    Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.

    Published: 30 May 2014
    2.1
    Low

    CVE-2013-4143

    Last Modified: 12 Apr 2025

    The (1) checkPasswd and (2) checkGroupXlockPasswds functions in xlockmore before 5.43 do not properly handle when a NULL value is returned upon an error by the crypt or dispcrypt function as implemented in glibc 2.17 and later, which allows attackers to bypass the screen lock via vectors related to invalid salts.

    Published: 30 May 2014
    4.3
    Medium

    CVE-2014-3922

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Trend Micro InterScan Messaging Security Virtual Appliance 8.5.1.1516 allows remote authenticated users to inject arbitrary web script or HTML via the addWhiteListDomainStr parameter to addWhiteListDomain.imss.

    Published: 30 May 2014
    4.3
    Medium

    CVE-2014-3924

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Webmin before 1.690 and Usermin before 1.600 allow remote attackers to inject arbitrary web script or HTML via vectors related to popup windows.

    Published: 30 May 2014
    7.5
    High

    CVE-2014-3780

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspecified vectors, related to a Java servlet.

    Published: 30 May 2014
    4.3
    Medium

    CVE-2014-3921

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in popup.php in the Simple Popup Images plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the z parameter.

    Published: 30 May 2014
    4.3
    Medium

    CVE-2014-3923

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the logoLink parameter to (1) preview.swf, (2) preview_skin_rouge.swf, (3) preview_allchars.swf, or (4) preview_skin_overlay.swf in deploy/.

    Published: 30 May 2014
    Unknown

    CVE-2014-3463

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a unique security issue. Notes: none

    Published: 30 May 2014
    5
    Medium

    CVE-2014-0095

    Last Modified: 12 Apr 2025

    java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.

    Published: 30 May 2014
    6.8
    Medium

    CVE-2014-3466

    Last Modified: 12 Apr 2025

    Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

    Published: 30 May 2014
    4
    Medium

    CVE-2014-3282

    Last Modified: 12 Apr 2025

    The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive number-translation information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum76930.

    Published: 29 May 2014
    5.8
    Medium

    CVE-2014-3283

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCun79731.

    Published: 29 May 2014
    4
    Medium

    CVE-2014-3277

    Last Modified: 12 Apr 2025

    The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive user and group information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum77005.

    Published: 29 May 2014
    5
    Medium

    CVE-2014-3279

    Last Modified: 12 Apr 2025

    The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSCun39631 and CSCun39643.

    Published: 29 May 2014
    5
    Medium

    CVE-2014-3285

    Last Modified: 12 Apr 2025

    Cisco Wide Area Application Services (WAAS) 5.3(.5a) and earlier, when SharePoint acceleration is enabled, does not properly parse SharePoint responses, which allows remote attackers to cause a denial of service (application-optimization handler reload) via a crafted SharePoint application, aka Bug ID CSCue47674.

    Published: 29 May 2014
    5
    Medium

    CVE-2013-4178

    Last Modified: 12 Apr 2025

    The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP).

    Published: 29 May 2014
    6.5
    Medium

    CVE-2014-3417

    Last Modified: 12 Apr 2025

    uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to configure portlets by leveraging the SUBSCRIBE permission for a portlet.

    Published: 29 May 2014
    5
    Medium

    CVE-2012-4915

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php.

    Published: 29 May 2014
    5
    Medium

    CVE-2013-4177

    Last Modified: 12 Apr 2025

    The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, which might allow remote attackers to bypass the two-factor authentication requirement via unspecified vectors.

    Published: 29 May 2014
    6.8
    Medium

    CVE-2014-3414

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authentication of administrators for requests that add administrative privileges to a user via the admin parameter to admin/administrators.

    Published: 29 May 2014
    6.5
    Medium

    CVE-2014-3415

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] parameter to the /invite page for a group.

    Published: 29 May 2014
    6.5
    Medium

    CVE-2014-3416

    Last Modified: 12 Apr 2025

    uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by leveraging the SUBSCRIBE permission for the portlet-admin portlet.

    Published: 29 May 2014
    5
    Medium

    CVE-2013-6470

    Last Modified: 12 Apr 2025

    The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenStack Platform 4.0, disables authentication for Qpid, which allows remote attackers to gain access by connecting to Qpid.

    Published: 29 May 2014
    5
    Medium

    CVE-2014-0237

    Last Modified: 12 Apr 2025

    The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.

    Published: 29 May 2014
    7.6
    High

    CVE-2013-6433

    Last Modified: 12 Apr 2025

    The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration file.

    Published: 29 May 2014
    5
    Medium

    CVE-2014-0238

    Last Modified: 12 Apr 2025

    The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero length or (2) is too long.

    Published: 29 May 2014
    5
    Medium

    CVE-2014-3925

    Last Modified: 12 Apr 2025

    sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

    Published: 29 May 2014
    7.5
    High

    CVE-2014-0250

    Last Modified: 12 Apr 2025

    Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to the (1) xf_Pointer_New or (2) xf_Bitmap_Decompress function, which causes an incorrect amount of memory to be allocated.

    Published: 28 May 2014
    6.8
    Medium

    CVE-2014-2957

    Last Modified: 12 Apr 2025

    The dmarc_process function in dmarc.c in Exim before 4.82.1, when EXPERIMENTAL_DMARC is enabled, allows remote attackers to execute arbitrary code via the From header in an email, which is passed to the expand_string function.

    Published: 28 May 2014
    3.5
    Low

    CVE-2014-0178

    Last Modified: 12 Apr 2025

    Samba 3.6.6 through 3.6.23, 4.0.x before 4.0.18, and 4.1.x before 4.1.8, when a certain vfs shadow copy configuration is enabled, does not properly initialize the SRV_SNAPSHOT_ARRAY response field, which allows remote authenticated users to obtain potentially sensitive information from process memory via a (1) FSCTL_GET_SHADOW_COPY_DATA or (2) FSCTL_SRV_ENUMERATE_SNAPSHOTS request.

    Published: 28 May 2014
    5
    Medium

    CVE-2014-0239

    Last Modified: 12 Apr 2025

    The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sending a response, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged response packet that triggers a communication loop, a related issue to CVE-1999-0103.

    Published: 28 May 2014
    8.8
    High

    CVE-2014-0225

    Last Modified: 20 Apr 2025

    When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

    Published: 28 May 2014
    3.3
    Low

    CVE-2014-3917

    Last Modified: 12 Apr 2025

    kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.

    Published: 28 May 2014