CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2014-3759

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the BibTex Publications (si_bibtex) extension 0.2.3 for TYPO3 allow remote attackers to execute arbitrary SQL commands via vectors related to the (1) search or (2) list functionality.

    Published: 16 May 2014
    10
    Critical

    CVE-2014-0749

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x through 2.5.13 allows remote attackers to execute arbitrary code via a large count value.

    Published: 16 May 2014
    4.3
    Medium

    CVE-2014-3761

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in D-Link DAP 1150 with firmware 1.2.94 allows remote attackers to inject arbitrary web script or HTML via the res_buf parameter to index.cgi in the Control/URL-filter section.

    Published: 16 May 2014
    7.9
    High

    CVE-2014-1649

    Last Modified: 12 Apr 2025

    The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS.

    Published: 16 May 2014
    7.6
    High

    CVE-2014-0643

    Last Modified: 12 Apr 2025

    EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid account name.

    Published: 16 May 2014
    4.3
    Medium

    CVE-2014-0917

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 16 May 2014
    7.1
    High

    CVE-2014-0918

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in IBM Eclipse Help System (IEHS) in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF27, and 8.0 before 8.0.0.1 CF06 allows remote attackers to read arbitrary files via a crafted URL.

    Published: 16 May 2014
    6.8
    Medium

    CVE-2014-0933

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM InfoSphere Information Server Metadata Workbench 8.1 through 9.1 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 16 May 2014
    7.1
    High

    CVE-2014-0964

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.

    Published: 16 May 2014
    4.3
    Medium

    CVE-2014-3262

    Last Modified: 12 Apr 2025

    The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.3(3)S and earlier and IOS XE does not properly validate parameters in ITR control messages, which allows remote attackers to cause a denial of service (CEF outage and packet drops) via malformed messages, aka Bug ID CSCun73782.

    Published: 16 May 2014
    5.4
    Medium

    CVE-2014-3263

    Last Modified: 12 Apr 2025

    The ScanSafe module in Cisco IOS 15.3(3)M allows remote attackers to cause a denial of service (device reload) via HTTPS packets that require tower processing, aka Bug ID CSCum97038.

    Published: 16 May 2014
    5.8
    Medium

    CVE-2014-3750

    Last Modified: 12 Apr 2025

    The Bilyoner application before 2.3.1 for Android and before 4.6.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 16 May 2014
    8.3
    High

    CVE-2014-0782

    Last Modified: 25 Sept 2025

    Stack-based buffer overflow in BKESimmgr.exe in the Expanded Test Functions package in Yokogawa CENTUM CS 1000, CENTUM CS 3000 Entry Class R3.09.50 and earlier, CENTUM VP R5.03.00 and earlier, CENTUM VP Entry Class R5.03.00 and earlier, Exaopc R3.71.02 and earlier, B/M9000CS R5.05.01 and earlier, and B/M9000 VP R7.03.01 and earlier allows remote attackers to execute arbitrary code via a crafted packet.

    Published: 16 May 2014
    2.1
    Low

    CVE-2014-4703

    Last Modified: 12 Apr 2025

    lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.

    Published: 16 May 2014
    2.1
    Low

    CVE-2014-4702

    Last Modified: 12 Apr 2025

    The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4701.

    Published: 16 May 2014
    2.1
    Low

    CVE-2014-4701

    Last Modified: 12 Apr 2025

    The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.

    Published: 16 May 2014
    10
    Critical

    CVE-2013-4730

    Last Modified: 19 Aug 2026

    Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command.

    Published: 15 May 2014
    4.3
    Medium

    CVE-2014-3247

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the desc parameter in an Add project (addpro) action to admin.php.

    Published: 15 May 2014
    7.5
    High

    CVE-2014-3757

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attackers to execute arbitrary SQL commands via the sorter_value parameter.

    Published: 15 May 2014
    4.3
    Medium

    CVE-2013-0197

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the filter_draw_selection_area2 function in core/filter_api.php in MantisBT 1.2.12 before 1.2.13 allows remote attackers to inject arbitrary web script or HTML via the match_type parameter to bugs/search.php.

    Published: 15 May 2014
    2.1
    Low

    CVE-2013-1810

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in core/summary_api.php in MantisBT 1.2.12 allow remote authenticated users with manager or administrator permissions to inject arbitrary web script or HTML via a (1) category name in the summary_print_by_category function or (2) project name in the summary_print_by_project function.

    Published: 15 May 2014
    4.3
    Medium

    CVE-2013-5939

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject arbitrary web script or HTML via the (1) list or (2) introduce parameter to index.php.

    Published: 14 May 2014
    6.8
    Medium

    CVE-2013-7376

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijack the authentication of administrators, as demonstrated by requests that conduct directory traversal attacks via the group parameter to (1) plugin-preferences.php or (2) plugin-settings.php in www/admin, a different vulnerability than CVE-2013-3514.

    Published: 14 May 2014
    4.3
    Medium

    CVE-2013-2087

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movies.php or (2) key variable to modules/gallery/views/error_admin.html.php.

    Published: 14 May 2014
    4.3
    Medium

    CVE-2011-5249

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the events page in the System iNtrusion Analysis and Reporting Environment (SNARE) for Linux agent before 1.7.0 allows remote attackers to inject arbitrary web script or HTML via a logged shell command.

    Published: 14 May 2014
    7.5
    High

    CVE-2013-2226

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.

    Published: 14 May 2014
    6.8
    Medium

    CVE-2013-2700

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Add/Edit page (adminmenus.php) in the WP125 plugin before 1.5.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that add or edit an ad via unspecified vectors.

    Published: 14 May 2014
    6.4
    Medium

    CVE-2013-5655

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote attackers to read and possibly write arbitrary files via a .. (dot dot) in the default URI.

    Published: 14 May 2014
    4.3
    Medium

    CVE-2014-1603

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) param parameter to admin/load.php or (2) user, (3) email, or (4) name parameter in a Save Settings action to admin/settings.php.

    Published: 14 May 2014
    4.3
    Medium

    CVE-2013-1765

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in jwplayer.swf in the smart-flv plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) link or (2) playerready parameter.

    Published: 14 May 2014
    4.3
    Medium

    CVE-2013-3514

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot dot) in the group parameter to (1) plugin-preferences.php or (2) plugin-settings.php in www/admin, a different vulnerability than CVE-2013-7376. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to read arbitrary files.

    Published: 14 May 2014
    6.5
    Medium

    CVE-2013-4468

    Last Modified: 12 Apr 2025

    VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.

    Published: 14 May 2014
    4.3
    Medium

    CVE-2014-3441

    Last Modified: 12 Apr 2025

    codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as demonstrated by a png in a .wave file.

    Published: 14 May 2014
    4.3
    Medium

    CVE-2014-3443

    Last Modified: 12 Apr 2025

    JetMPAd.ax in JetAudio 8.1.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file.

    Published: 14 May 2014
    8.8
    High

    CVE-2014-1812

    Last Modified: 22 Apr 2026

    The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka "Group Policy Preferences Password Elevation of Privilege Vulnerability."

    Published: 14 May 2014
    10
    Critical

    CVE-2014-0522

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0523, CVE-2014-0524, and CVE-2014-0526.

    Published: 14 May 2014
    10
    Critical

    CVE-2014-0525

    Last Modified: 12 Apr 2025

    The API in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X does not prevent access to unmapped memory, which allows attackers to execute arbitrary code via unspecified API calls.

    Published: 14 May 2014
    10
    Critical

    CVE-2014-0527

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.

    Published: 14 May 2014
    4.3
    Medium

    CVE-2014-1754

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."

    Published: 14 May 2014
    7.2
    High

    CVE-2014-1807

    Last Modified: 12 Apr 2025

    The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly implement file associations, which allows local users to gain privileges via a crafted application, as exploited in the wild in May 2014, aka "Windows Shell File Association Vulnerability."

    Published: 14 May 2014
    6.8
    Medium

    CVE-2014-1809

    Last Modified: 12 Apr 2025

    The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted web site, as exploited in the wild in May 2014, aka "MSCOMCTL ASLR Vulnerability."

    Published: 14 May 2014
    5
    Medium

    CVE-2014-0255

    Last Modified: 12 Apr 2025

    Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vulnerability."

    Published: 14 May 2014
    5
    Medium

    CVE-2014-0256

    Last Modified: 12 Apr 2025

    Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vulnerability."

    Published: 14 May 2014
    9.3
    Critical

    CVE-2014-0310

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1815.

    Published: 14 May 2014
    10
    Critical

    CVE-2014-0513

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Adobe Illustrator CS6 before 16.0.5 and 16.2.x before 16.2.2 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 14 May 2014
    10
    Critical

    CVE-2014-0523

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0522, CVE-2014-0524, and CVE-2014-0526.

    Published: 14 May 2014
    10
    Critical

    CVE-2014-0524

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0522, CVE-2014-0523, and CVE-2014-0526.

    Published: 14 May 2014
    10
    Critical

    CVE-2014-0526

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0522, CVE-2014-0523, and CVE-2014-0524.

    Published: 14 May 2014
    10
    Critical

    CVE-2014-0529

    Last Modified: 12 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors.

    Published: 14 May 2014
    7.5
    High

    CVE-2014-1740

    Last Modified: 12 Apr 2025

    Multiple use-after-free vulnerabilities in net/websockets/websocket_job.cc in the WebSockets implementation in Google Chrome before 34.0.1847.137 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to WebSocketJob deletion.

    Published: 14 May 2014