CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2014-3115

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers to hijack the authentication of administrators via system/config/adminadd and other unspecified vectors.

    Published: 8 May 2014
    2.1
    Low

    CVE-2014-3123

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/manage-images.php in the NextCellent Gallery plugin before 1.19.18 for WordPress allows remote authenticated users with the NextGEN Upload images, NextGEN Manage gallery, or NextGEN Manage others gallery permission to inject arbitrary web script or HTML via the "Alt & Title Text" field.

    Published: 8 May 2014
    9.3
    Critical

    CVE-2014-2134

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted audio channel in a .wrf file, aka Bug ID CSCuc39458.

    Published: 8 May 2014
    2.1
    Low

    CVE-2014-3425

    Last Modified: 12 Apr 2025

    NCSA Mosaic 2.0 and earlier allows local users to cause a denial of service ("remote control" outage) by creating a /tmp/xmosaic.pid file for every possible PID.

    Published: 8 May 2014
    2.1
    Low

    CVE-2014-3426

    Last Modified: 12 Apr 2025

    NCSA Mosaic 2.1 through 2.7b5 allows local users to cause a denial of service ("remote control" outage) by creating a /tmp/Mosaic.pid file for every possible PID.

    Published: 8 May 2014
    6.5
    Medium

    CVE-2014-2602

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP OneView 1.0 and 1.01 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 8 May 2014
    7.6
    High

    CVE-2013-5016

    Last Modified: 12 Apr 2025

    Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform, allows remote attackers to bypass policy settings via unspecified vectors.

    Published: 8 May 2014
    4.3
    Medium

    CVE-2014-0362

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability on Google Search Appliance (GSA) devices before 7.0.14.G.216 and 7.2 before 7.2.0.G.114, when dynamic navigation is configured, allows remote attackers to inject arbitrary web script or HTML via input included in a SCRIPT element.

    Published: 8 May 2014
    2.6
    Low

    CVE-2014-0595

    Last Modified: 12 Apr 2025

    /opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the granting of the F permission by an administrator.

    Published: 8 May 2014
    7.1
    High

    CVE-2014-0963

    Last Modified: 12 Apr 2025

    The Reverse Proxy feature in IBM Global Security Kit (aka GSKit) in IBM Security Access Manager (ISAM) for Web 7.0 before 7.0.0-ISS-SAM-IF0006 and 8.0 before 8.0.0.3-ISS-WGA-IF0002 allows remote attackers to cause a denial of service (infinite loop) via crafted SSL messages.

    Published: 8 May 2014
    7.8
    High

    CVE-2014-2132

    Last Modified: 12 Apr 2025

    Cisco WebEx Recording Format (WRF) player and Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allow remote attackers to cause a denial of service (application crash) via a crafted (1) .wrf or (2) .arf file that triggers a buffer over-read, aka Bug ID CSCuh52768.

    Published: 8 May 2014
    9.3
    Critical

    CVE-2014-2133

    Last Modified: 12 Apr 2025

    Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file that triggers improper LZW decompression, aka Bug ID CSCuj87565.

    Published: 8 May 2014
    9.3
    Critical

    CVE-2014-2136

    Last Modified: 12 Apr 2025

    Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file, aka Bug IDs CSCui72223, CSCul01163, and CSCul01166.

    Published: 8 May 2014
    4.7
    Medium

    CVE-2014-0930

    Last Modified: 12 Apr 2025

    The ptrace system call in IBM AIX 5.3, 6.1, and 7.1, and VIOS 2.2.x, allows local users to cause a denial of service (system crash) or obtain sensitive information from kernel memory via a crafted PT_LDINFO operation.

    Published: 8 May 2014
    9.3
    Critical

    CVE-2014-2135

    Last Modified: 12 Apr 2025

    Buffer overflow in Cisco Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T28 before T28.12, and T29 before T29.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted .arf file, aka Bug IDs CSCul87216 and CSCuj07603.

    Published: 8 May 2014
    5
    Medium

    CVE-2014-2933

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in dirmng/index.php in Caldera 9.20 allows remote attackers to access arbitrary directories via a crafted pathname.

    Published: 8 May 2014
    7.5
    High

    CVE-2014-2934

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the tr parameter to (1) costview2/jobs.php or (2) costview2/printers.php.

    Published: 8 May 2014
    10
    Critical

    CVE-2014-2935

    Last Modified: 12 Apr 2025

    costview3/xmlrpc_server/xmlrpc.php in CostView in Caldera 9.20 allows remote attackers to execute arbitrary commands via shell metacharacters in a methodCall element in a PHP XMLRPC request.

    Published: 8 May 2014
    7.5
    High

    CVE-2014-2936

    Last Modified: 12 Apr 2025

    The directory manager in Caldera 9.20 allows remote attackers to conduct variable-injection attacks in the global scope via (1) the maindir_hotfolder parameter to dirmng/index.php, or an unspecified parameter to (2) PPD/index.php, (3) dirmng/docmd.php, or (4) dirmng/param.php.

    Published: 8 May 2014
    4
    Medium

    CVE-2014-3225

    Last Modified: 12 Apr 2025

    Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.

    Published: 8 May 2014
    5.4
    Medium

    CVE-2014-0208

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the search auto-completion functionality in Foreman before 1.4.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted key name.

    Published: 8 May 2014
    5
    Medium

    CVE-2014-3214

    Last Modified: 12 Apr 2025

    The prefetch implementation in named in ISC BIND 9.10.0, when a recursive nameserver is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a DNS query that triggers a response with unspecified attributes.

    Published: 8 May 2014
    5
    Medium

    CVE-2014-0685

    Last Modified: 12 Apr 2025

    Cisco Nexus 1000V InterCloud 5.2(1)IC1(1.2) and earlier for VMware allows remote attackers to bypass ACL deny statements via crafted (1) IGMPv2 or (2) IGMPv3 packets, aka Bug ID CSCug61691.

    Published: 7 May 2014
    4.3
    Medium

    CVE-2014-0911

    Last Modified: 12 Apr 2025

    inetd in IBM WebSphere MQ 7.1.x before 7.1.0.5 and 7.5.x before 7.5.0.4 allows remote attackers to cause a denial of service (disk or CPU consumption) via unspecified vectors.

    Published: 7 May 2014
    3.5
    Low

    CVE-2013-6726

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3.x before 3.3.1.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 May 2014
    4.6
    Medium

    CVE-2014-0684

    Last Modified: 12 Apr 2025

    Cisco NX-OS 6.2(2) on Nexus 7000 switches allows local users to cause a denial of service via crafted sed input, aka Bug ID CSCui56136.

    Published: 7 May 2014
    6.8
    Medium

    CVE-2014-2181

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software allows remote authenticated users to read files by sending a crafted URL to the HTTP server, as demonstrated by reading the running configuration, aka Bug ID CSCun78551.

    Published: 7 May 2014
    6.8
    Medium

    CVE-2014-2190

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows remote attackers to hijack the authentication of arbitrary users for requests that make BAC-TW changes, aka Bug IDs CSCuo23804 and CSCuo26389.

    Published: 7 May 2014
    4.3
    Medium

    CVE-2014-2191

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun91113.

    Published: 7 May 2014
    2.1
    Low

    CVE-2014-1738

    Last Modified: 12 Apr 2025

    The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.

    Published: 7 May 2014
    7.2
    High

    CVE-2014-1737

    Last Modified: 12 Apr 2025

    The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.

    Published: 7 May 2014
    7.5
    High

    CVE-2014-3775

    Last Modified: 12 Apr 2025

    libgadu before 1.11.4 and 1.12.0 before 1.12.0-rc3, as used in Pidgin and other products, allows remote Gadu-Gadu file relay servers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted message.

    Published: 7 May 2014
    4.4
    Medium

    CVE-2014-3203

    Last Modified: 12 Apr 2025

    Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is active, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by pressing the SUPER key before the screen auto-locks.

    Published: 6 May 2014
    6.5
    Medium

    CVE-2014-2558

    Last Modified: 12 Apr 2025

    The File Gallery plugin before 1.7.9.2 for WordPress does not properly escape strings, which allows remote administrators to execute arbitrary PHP code via a \' (backslash quote) in the setting fields to /wp-admin/options-media.php, related to the create_function function.

    Published: 6 May 2014
    4.4
    Medium

    CVE-2014-3202

    Last Modified: 12 Apr 2025

    Unity before 7.2.1 does not properly handle entry activation, which allows physically proximate attackers to bypass the lock screen by holding the ENTER key, which triggers the process to crash.

    Published: 6 May 2014
    4.4
    Medium

    CVE-2014-3204

    Last Modified: 12 Apr 2025

    Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by right-clicking on the indicator bar and then pressing the ALT and F2 keys.

    Published: 6 May 2014
    7
    High

    CVE-2014-2347

    Last Modified: 2 Oct 2025

    Amtelco miSecureMessages (aka MSM) 6.2 does not properly manage sessions, which allows remote authenticated users to obtain sensitive information via a modified message request.

    Published: 6 May 2014
    7.5
    High

    CVE-2014-0130

    Last Modified: 21 Apr 2026

    Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.

    Published: 6 May 2014
    1.9
    Low

    CVE-2014-0179

    Last Modified: 12 Apr 2025

    libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT per ADT3 due to different affected versions of some vectors. CVE-2014-5177 is used for other API methods.

    Published: 6 May 2014
    4.3
    Medium

    CVE-2014-0191

    Last Modified: 12 Apr 2025

    The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.

    Published: 6 May 2014
    1.2
    Low

    CVE-2014-5177

    Last Modified: 12 Apr 2025

    libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3) virNetworkDefineXML, (4) virStoragePoolCreateXML, (5) virStoragePoolDefineXML, (6) virStorageVolCreateXML, (7) virDomainCreateXML, (8) virNodeDeviceCreateXML, (9) virInterfaceDefineXML, (10) virStorageVolCreateXMLFrom, (11) virConnectDomainXMLFromNative, (12) virConnectDomainXMLToNative, (13) virSecretDefineXML, (14) virNWFilterDefineXML, (15) virDomainSnapshotCreateXML, (16) virDomainSaveImageDefineXML, (17) virDomainCreateXMLWithFiles, (18) virConnectCompareCPU, or (19) virConnectBaselineCPU API method, related to an XML External Entity (XXE) issue. NOTE: this issue was SPLIT from CVE-2014-0179 per ADT3 due to different affected versions of some vectors.

    Published: 6 May 2014
    7.5
    High

    CVE-2013-1803

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby parameter to downloads.php; or remote authenticated users with certain permissions to execute arbitrary SQL commands via a (2) parameter name starting with "delete_attach_" in an edit action to forum/postedit.php; the (3) poll_opts[] parameter in a newthread action to forum/postnewthread.php; the (4) pm_email_notify, (5) pm_save_sent, (6) pm_inbox, (7) pm_sentbox, or (8) pm_savebox parameter to administration/settings_messages.php; the (9) thumb_compression, (10) photo_watermark_text_color1, (11) photo_watermark_text_color2, or (12) photo_watermark_text_color3 parameter to administration/settings_photo.php; the (13) enable parameter to administration/bbcodes.php; the (14) news_image, (15) news_image_t1, or (16) news_image_t2 parameter to administration/news.php; the (17) news_id parameter in an edit action to administration/news.php; or the (18) article_id parameter in an edit action to administration/articles.php. NOTE: the user ID cookie issue in Authenticate.class.php is already covered by CVE-2013-7375.

    Published: 5 May 2014
    4.3
    Medium

    CVE-2013-7003

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) full name field, (2) company field, or (3) filename to chat.php.

    Published: 5 May 2014
    7.5
    High

    CVE-2013-7034

    Last Modified: 12 Apr 2025

    The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP code via a serialized PHP object in a cookie.

    Published: 5 May 2014
    4.3
    Medium

    CVE-2010-5109

    Last Modified: 12 Apr 2025

    Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of service (crash) via a crafted TNEF file, which triggers a buffer overflow.

    Published: 5 May 2014
    7.5
    High

    CVE-2013-7375

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitrary SQL commands via the user ID in a user cookie, a different vulnerability than CVE-2013-1803.

    Published: 5 May 2014
    6.3
    Medium

    CVE-2013-0350

    Last Modified: 12 Apr 2025

    tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.

    Published: 5 May 2014
    4.3
    Medium

    CVE-2013-3736

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the name of an attached file.

    Published: 5 May 2014
    9
    Critical

    CVE-2014-3220

    Last Modified: 12 Apr 2025

    F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/.

    Published: 5 May 2014
    6.8
    Medium

    CVE-2014-2916

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the subscription page editor (spageedit) in phpList before 3.0.6 allows remote attackers to hijack the authentication of administrators via a request to admin/.

    Published: 5 May 2014