CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-0949

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to cause a denial of service (resource consumption and daemon crash) via a crafted web request.

    Published: 22 May 2014
    4.3
    Medium

    CVE-2014-0956

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in googlemap.jsp in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 May 2014
    4.3
    Medium

    CVE-2014-0951

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in FilterForm.jsp in IBM WebSphere Portal 7.0 before 7.0.0.2 CF28 and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 May 2014
    4.3
    Medium

    CVE-2014-0952

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in boot_config.jsp in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF28, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 May 2014
    6.8
    Medium

    CVE-2014-0954

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 does not validate JSP includes, which allows remote attackers to obtain sensitive information, bypass intended request-dispatcher access restrictions, or cause a denial of service (memory consumption) via a crafted URL.

    Published: 22 May 2014
    4.3
    Medium

    CVE-2014-0955

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0 before 8.0.0.1 CF12, when Social Rendering in Connections integration is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 May 2014
    5.8
    Medium

    CVE-2014-0958

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 22 May 2014
    4
    Medium

    CVE-2014-0959

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, and 8.0 before 8.0.0.1 CF12 allows remote authenticated users to cause a denial of service (infinite loop) via a login redirect.

    Published: 22 May 2014
    9.3
    Critical

    CVE-2014-1770

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.

    Published: 22 May 2014
    5
    Medium

    CVE-2014-2604

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP IceWall SSO 10.0 Dfw and IceWall MCRP 2.1 and 3.0 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 22 May 2014
    5
    Medium

    CVE-2014-3806

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the xml_path parameter.

    Published: 21 May 2014
    10
    Critical

    CVE-2012-1166

    Last Modified: 12 Apr 2025

    The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.

    Published: 21 May 2014
    4.3
    Medium

    CVE-2014-3807

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) blog, (2) bloggeruser, or (3) bloggerpasswd parameter to private/manage/.

    Published: 21 May 2014
    4.3
    Medium

    CVE-2014-3808

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) role parameter to roles.lsp, (2) name parameter to user.lsp, (3) path parameter to wizard/setuser.lsp, (4) host parameter to tunnelconstr.lsp, or (5) newpath parameter to wfsconstr.lsp in rtl/protected/admin/.

    Published: 21 May 2014
    4.3
    Medium

    CVE-2014-1747

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."

    Published: 21 May 2014
    4.3
    Medium

    CVE-2014-3803

    Last Modified: 12 Apr 2025

    The SpeechInput feature in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to enable microphone access and obtain speech-recognition text without indication via an INPUT element with a -x-webkit-speech attribute.

    Published: 21 May 2014
    7.5
    High

    CVE-2014-1743

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the StyleElement::removedFromDocument function in core/dom/StyleElement.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers tree mutation.

    Published: 21 May 2014
    7.5
    High

    CVE-2014-1744

    Last Modified: 12 Apr 2025

    Integer overflow in the AudioInputRendererHost::OnCreateStream function in content/browser/renderer_host/media/audio_input_renderer_host.cc in Google Chrome before 35.0.1916.114 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large shared-memory allocation.

    Published: 21 May 2014
    5
    Medium

    CVE-2014-1746

    Last Modified: 12 Apr 2025

    The InMemoryUrlProtocol::Read function in media/filters/in_memory_url_protocol.cc in Google Chrome before 35.0.1916.114 relies on an insufficiently large integer data type, which allows remote attackers to cause a denial of service (out-of-bounds read) via vectors that trigger use of a large buffer.

    Published: 21 May 2014
    7.5
    High

    CVE-2014-1749

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 35.0.1916.114 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 21 May 2014
    5
    Medium

    CVE-2014-1748

    Last Modified: 12 Apr 2025

    The ScrollView::paint function in platform/scroll/ScrollView.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to spoof the UI by extending scrollbar painting into the parent frame.

    Published: 21 May 2014
    7.1
    High

    CVE-2014-1745

    Last Modified: 4 Jun 2025

    Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger removal of an SVGFontFaceElement object, related to core/svg/SVGFontFaceElement.cpp.

    Published: 21 May 2014
    6.5
    Medium

    CVE-2014-0204

    Last Modified: 12 Apr 2025

    OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

    Published: 21 May 2014
    6.5
    Medium

    CVE-2014-0233

    Last Modified: 12 Apr 2025

    Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters in a directory name that is referenced by a cartridge using the file: URI scheme.

    Published: 21 May 2014
    6.2
    Medium

    CVE-2014-0240

    Last Modified: 12 Apr 2025

    The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain Linux kernels, which allows local users to gain privileges via vectors related to the number of running processes.

    Published: 21 May 2014
    7.5
    High

    CVE-2014-0242

    Last Modified: 21 Nov 2024

    mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.

    Published: 21 May 2014
    1.9
    Low

    CVE-2014-3956

    Last Modified: 12 Apr 2025

    The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.

    Published: 21 May 2014
    6.8
    Medium

    CVE-2014-3802

    Last Modified: 12 Apr 2025

    msdia.dll in Microsoft Debug Interface Access (DIA) SDK, as distributed in Microsoft Visual Studio before 2013, does not properly validate an unspecified variable before use in calculating a dynamic-call address, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDB file.

    Published: 20 May 2014
    6.5
    Medium

    CVE-2013-4250

    Last Modified: 12 Apr 2025

    The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.

    Published: 20 May 2014
    5.5
    Medium

    CVE-2013-4320

    Last Modified: 12 Apr 2025

    The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenticated users to create or read arbitrary files via a crafted URL.

    Published: 20 May 2014
    6.5
    Medium

    CVE-2013-4321

    Last Modified: 12 Apr 2025

    The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code via unspecified characters in the file extension when renaming a file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4250.

    Published: 20 May 2014
    2.1
    Low

    CVE-2013-4380

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MediaFront module 6.x-1.x before 6.x-1.6, 7.x-1.x before 7.x-1.6, and 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer mediafront" permission to inject arbitrary web script or HTML via the preset settings.

    Published: 20 May 2014
    6.8
    Medium

    CVE-2014-3792

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the uiViewTools_Password and uiViewTools_PasswordConfirm parameters to Forms/tools_admin_1.

    Published: 20 May 2014
    4.3
    Medium

    CVE-2014-3738

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the title of a device.

    Published: 20 May 2014
    5.8
    Medium

    CVE-2014-3739

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the came_from parameter.

    Published: 20 May 2014
    7.5
    High

    CVE-2014-3776

    Last Modified: 12 Apr 2025

    Buffer overflow in the "read-u8vector!" procedure in the srfi-4 unit in CHICKEN stable 4.8.0.7 and development snapshots before 4.9.1 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via a "#f" value in the NUM argument.

    Published: 20 May 2014
    10
    Critical

    CVE-2014-3791

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.ghp.

    Published: 20 May 2014
    4
    Medium

    CVE-2012-6146

    Last Modified: 12 Apr 2025

    The Backend History Module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 does not properly restrict access, which allows remote authenticated editors to read the history of arbitrary records via a crafted URL.

    Published: 20 May 2014
    9
    Critical

    CVE-2013-7383

    Last Modified: 12 Apr 2025

    x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain privileges via unspecified vectors, possibly related to backticks.

    Published: 20 May 2014
    4.3
    Medium

    CVE-2014-1855

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Seo Panel before 3.5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) capcheck parameter to directories.php or (2) keyword parameter to proxy.php.

    Published: 20 May 2014
    10
    Critical

    CVE-2014-3412

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Juniper Junos Space before 13.3R1.8, when the firewall in disabled, allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 20 May 2014
    7.5
    High

    CVE-2014-3749

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the email parameter to autenticar/lembrarlogin.asp.

    Published: 20 May 2014
    4.3
    Medium

    CVE-2014-2192

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unified Web and E-mail Interaction Manager 9.0(2) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuj43033.

    Published: 20 May 2014
    4.3
    Medium

    CVE-2014-2195

    Last Modified: 12 Apr 2025

    Cisco AsyncOS on Email Security Appliance (ESA) and Content Security Management Appliance (SMA) devices, when Active Directory is enabled, does not properly handle group names, which allows remote attackers to gain role privileges by leveraging group-name similarity, aka Bug ID CSCum86085.

    Published: 20 May 2014
    6.8
    Medium

    CVE-2014-3460

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted pathname.

    Published: 20 May 2014
    4.3
    Medium

    CVE-2014-3265

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuo06900.

    Published: 20 May 2014
    5
    Medium

    CVE-2014-3268

    Last Modified: 12 Apr 2025

    Cisco IOS 15.2(4)M4 on Cisco Unified Border Element (CUBE) devices allows remote attackers to cause a denial of service (input-queue consumption and traffic-processing outage) via crafted RTCP packets, aka Bug ID CSCuj72215.

    Published: 20 May 2014
    6.8
    Medium

    CVE-2014-3269

    Last Modified: 12 Apr 2025

    The SNMP module in Cisco IOS XE 3.5E allows remote authenticated users to cause a denial of service (device reload) by polling frequently, aka Bug ID CSCug65204.

    Published: 20 May 2014
    5
    Medium

    CVE-2014-3270

    Last Modified: 12 Apr 2025

    The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (process hang) via a malformed packet, aka Bug ID CSCul80924.

    Published: 20 May 2014
    5
    Medium

    CVE-2014-3271

    Last Modified: 12 Apr 2025

    The DHCPv6 implementation in Cisco IOS XR allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug IDs CSCum85558, CSCum20949, CSCul61849, and CSCul71149.

    Published: 20 May 2014