CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2014-3273

    Last Modified: 12 Apr 2025

    The LLDP implementation in Cisco IOS allows remote attackers to cause a denial of service (device reload) via a malformed packet, aka Bug ID CSCum96282.

    Published: 20 May 2014
    4.6
    Medium

    CVE-2013-6975

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier allows local users to read arbitrary files via unspecified input, aka Bug ID CSCul05217.

    Published: 20 May 2014
    6.8
    Medium

    CVE-2014-2194

    Last Modified: 12 Apr 2025

    system/egain/chat/entrypoint in Cisco Unified Web and E-mail Interaction Manager 9.0(2) allows remote attackers to have an unspecified impact by injecting a spoofed XML external entity.

    Published: 20 May 2014
    5
    Medium

    CVE-2014-2199

    Last Modified: 12 Apr 2025

    meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and earlier, and WebEx Business Suite (WBS) 27 before 27.32.31.16, 28 before 28.12.13.18, and 29 before 29.5.1.12 allows remote attackers to obtain sensitive meeting information by leveraging knowledge of a meeting identifier, aka Bug IDs CSCuo68624 and CSCue46738.

    Published: 20 May 2014
    4.3
    Medium

    CVE-2014-2193

    Last Modified: 12 Apr 2025

    Cisco Unified Web and E-Mail Interaction Manager places session identifiers in GET requests, which allows remote attackers to inject conversation text by obtaining a valid identifier, aka Bug ID CSCuj43084.

    Published: 20 May 2014
    6.3
    Medium

    CVE-2014-3264

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software 9.1(.5) and earlier allows remote authenticated users to cause a denial of service (device reload) via crafted attributes in a RADIUS packet, aka Bug ID CSCun69561.

    Published: 20 May 2014
    9.3
    Critical

    CVE-2014-3444

    Last Modified: 12 Apr 2025

    The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.

    Published: 20 May 2014
    7.5
    High

    CVE-2014-2351

    Last Modified: 3 Oct 2025

    SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.

    Published: 20 May 2014
    5
    Medium

    CVE-2014-4615

    Last Modified: 12 Apr 2025

    The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

    Published: 20 May 2014
    5
    Medium

    CVE-2013-4406

    Last Modified: 12 Apr 2025

    The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not properly check block permissions, which allows remote attackers to obtain sensitive information by reading a Quick Tab.

    Published: 19 May 2014
    3.6
    Low

    CVE-2013-4426

    Last Modified: 12 Apr 2025

    pyxtrlock before 0.1 uses an incorrect variable name, which allows physically proximate attackers to bypass the lock screen via multiple failed authentication attempts, which trigger a crash.

    Published: 19 May 2014
    2.1
    Low

    CVE-2013-4427

    Last Modified: 12 Apr 2025

    pyxtrlock before 0.2 does not properly check the return values of the (1) xcb_grab_pointer and (2) xcb_grab_keyboard XCB library functions, which allows physically proximate attackers to gain access to the keyboard or mouse without unlocking the screen via unspecified vectors.

    Published: 19 May 2014
    4
    Medium

    CVE-2013-4429

    Last Modified: 12 Apr 2025

    Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly restrict access to artefacts, which allows remote authenticated users to read arbitrary artefacts via the (1) artefact id in an upload action when creating a journal or (2) instconf_artefactid_selected[ID] parameter in an upload action when editing a block.

    Published: 19 May 2014
    4.3
    Medium

    CVE-2013-4430

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 allows remote attackers to inject arbitrary web script or HTML via the Host header to lib/web.php.

    Published: 19 May 2014
    5.5
    Medium

    CVE-2013-4431

    Last Modified: 12 Apr 2025

    Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request.

    Published: 19 May 2014
    4
    Medium

    CVE-2013-4432

    Last Modified: 12 Apr 2025

    Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not properly restrict access to folders, which allows remote authenticated users to read arbitrary folders (1) by leveraging an active folder tab loaded before permissions were removed or (2) via the folder parameter to artefact/file/groupfiles.php.

    Published: 19 May 2014
    6.8
    Medium

    CVE-2013-6806

    Last Modified: 12 Apr 2025

    OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.

    Published: 19 May 2014
    6.4
    Medium

    CVE-2013-6994

    Last Modified: 12 Apr 2025

    OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.

    Published: 19 May 2014
    4.3
    Medium

    CVE-2013-7033

    Last Modified: 12 Apr 2025

    LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might allow remote attackers to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack.

    Published: 19 May 2014
    6.8
    Medium

    CVE-2013-7385

    Last Modified: 12 Apr 2025

    LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which allows remote attackers to obtain sensitive information and gain privileges by accessing the loginName and loginPassword variables using an independent cross-site scripting (XSS) attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7033.

    Published: 19 May 2014
    Unknown

    CVE-2013-6764

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-6795. Reason: This candidate is a duplicate of CVE-2013-6795. A typo in an external publication caused this ID to be associated with the wrong vulnerability. Notes: All CVE users should reference CVE-2013-6795 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 May 2014
    7.5
    High

    CVE-2013-6765

    Last Modified: 12 Apr 2025

    OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.

    Published: 19 May 2014
    7.5
    High

    CVE-2013-6766

    Last Modified: 12 Apr 2025

    OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP commands via a crafted OAP request for version information, which causes the state to be set to CLIENT_AUTHENTIC.

    Published: 19 May 2014
    5
    Medium

    CVE-2013-6805

    Last Modified: 12 Apr 2025

    OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a .eod8 file.

    Published: 19 May 2014
    5
    Medium

    CVE-2013-7384

    Last Modified: 12 Apr 2025

    UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors, related to SSL. NOTE: this issue was SPLIT from CVE-2013-6413 per ADT2 due to different vulnerability types.

    Published: 19 May 2014
    5
    Medium

    CVE-2013-6413

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7384 was assigned for the NULL pointer dereference.

    Published: 19 May 2014
    6.8
    Medium

    CVE-2013-6807

    Last Modified: 12 Apr 2025

    The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.

    Published: 19 May 2014
    10
    Critical

    CVE-2014-3411

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the NSM XDB service in Juniper NSM before 2012.2R8 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 19 May 2014
    3.3
    Low

    CVE-2014-3714

    Last Modified: 12 Apr 2025

    The ARM image loading functionality in Xen 4.4.x does not properly validate kernel length, which allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit ARM guest kernel in an image, which triggers a buffer overflow.

    Published: 19 May 2014
    4.3
    Medium

    CVE-2014-3735

    Last Modified: 12 Apr 2025

    ir41_32.ax 4.51.16.3 for Intel Indeo Video 4.5 allows remote attackers to cause a denial of service (crash) via a crafted .avi file.

    Published: 19 May 2014
    3.3
    Low

    CVE-2014-3715

    Last Modified: 12 Apr 2025

    Buffer overflow in Xen 4.4.x allows local users to read system memory or cause a denial of service (crash) via a crafted 32-bit guest kernel, related to searching for an appended DTB.

    Published: 19 May 2014
    1.9
    Low

    CVE-2014-3716

    Last Modified: 12 Apr 2025

    Xen 4.4.x does not properly check alignment, which allows local users to cause a denial of service (crash) via an unspecified field in a DTB header in a 32-bit guest kernel.

    Published: 19 May 2014
    3.3
    Low

    CVE-2014-3717

    Last Modified: 12 Apr 2025

    Xen 4.4.x does not properly validate the load address for 64-bit ARM guest kernels, which allows local users to read system memory or cause a denial of service (crash) via a crafted kernel, which triggers a buffer overflow.

    Published: 19 May 2014
    5
    Medium

    CVE-2014-3787

    Last Modified: 12 Apr 2025

    SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors.

    Published: 19 May 2014
    9.8
    Critical

    CVE-2014-9761

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.

    Published: 19 May 2014
    5.9
    Medium

    CVE-2014-4616

    Last Modified: 20 Apr 2025

    Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

    Published: 19 May 2014
    4.7
    Medium

    CVE-2015-0296

    Last Modified: 20 Apr 2025

    The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allows local users to delete arbitrary files via a crafted file in the user's home directory.

    Published: 19 May 2014
    4.4
    Medium

    CVE-2014-1347

    Last Modified: 12 Apr 2025

    Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.

    Published: 18 May 2014
    6.5
    Medium

    CVE-2013-4489

    Last Modified: 12 Apr 2025

    The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands, as demonstrated by the search box for the GitLab code search feature.

    Published: 17 May 2014
    2.1
    Low

    CVE-2013-4498

    Last Modified: 12 Apr 2025

    The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group group spaces content when using the option to move to a new group, which causes the content to be "orphaned" and allows remote authenticated users with the "access content" permission to obtain sensitive information via vectors involving a rebuild access for the site or content.

    Published: 17 May 2014
    5
    Medium

    CVE-2013-7382

    Last Modified: 12 Apr 2025

    VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for remote attackers to obtain access.

    Published: 17 May 2014
    Unknown

    CVE-2014-2085

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2084. Reason: This issue was MERGED into CVE-2014-2084 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2014-2084 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 May 2014
    8.5
    High

    CVE-2014-2084

    Last Modified: 12 Apr 2025

    Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin interface, which allows remote attackers to obtain sensitive information via a request to (1) scripts/commands/getSystemInformation or (2) scripts/commands/getNetworkConfigurationInfo, cause a denial of service (reboot) via a request to scripts/commands/reboot, or cause a denial of service (shutdown) via a request to scripts/commands/shutdown.

    Published: 17 May 2014
    6.5
    Medium

    CVE-2014-3453

    Last Modified: 12 Apr 2025

    Eval injection vulnerability in the flag_import_form_validate function in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and earlier for Drupal allows remote authenticated administrators to execute arbitrary PHP code via the "Flag import code" text area to admin/structure/flags/import. NOTE: this issue could also be exploited by other attackers if the administrator ignores a security warning on the permissions assignment page.

    Published: 17 May 2014
    7.5
    High

    CVE-2014-1613

    Last Modified: 12 Apr 2025

    Dotclear before 2.6.2 allows remote attackers to execute arbitrary PHP code via a serialized object in the dc_passwd cookie to a password-protected page, which is not properly handled by (1) inc/public/lib.urlhandlers.php or (2) plugins/pages/_public.php.

    Published: 16 May 2014
    5
    Medium

    CVE-2014-3742

    Last Modified: 12 Apr 2025

    The hapi server framework 2.0.x and 2.1.x before 2.2.0 for Node.js allows remote attackers to cause a denial of service (file descriptor consumption and process crash) via unspecified vectors.

    Published: 16 May 2014
    6.8
    Medium

    CVE-2013-7379

    Last Modified: 12 Apr 2025

    The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which allows remote attackers to bypass authentication via a string in the access-key header that partially matches config.master.api.access_key.

    Published: 16 May 2014
    4.3
    Medium

    CVE-2014-3452

    Last Modified: 12 Apr 2025

    Filters\LAV\avfilter-lav-4.dll in K-lite Codec 10.4.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .jpg file.

    Published: 16 May 2014
    6.8
    Medium

    CVE-2014-3760

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DAP 1150 with firmware 1.2.94 allow remote attackers to hijack the authentication of administrators for requests that (1) enable or (2) disable the DMZ in the Firewall/DMZ section via a request to index.cgi or (3) add, (4) modify, or (5) delete URL-filter settings in the Control/URL-filter section via a request to index.cgi, as demonstrated by adding a rule that blocks access to google.com.

    Published: 16 May 2014
    4.3
    Medium

    CVE-2014-3758

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the BibTex Publications (si_bibtex) extension 0.2.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via vectors related to the import functionality.

    Published: 16 May 2014