CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2014-0469

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in a certain Debian patch for xbuffy before 3.3.bl.3.dfsg-9 allows remote attackers to execute arbitrary code via the subject of an email, possibly related to indent subject lines.

    Published: 5 May 2014
    3.5
    Low

    CVE-2014-5338

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the multisite component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors to the (1) render_status_icons function in htmllib.py or (2) ajax_action function in actions.py.

    Published: 5 May 2014
    9.3
    Critical

    CVE-2014-5340

    Last Modified: 12 Apr 2025

    The wato component in Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to an automation URL.

    Published: 5 May 2014
    5
    Medium

    CVE-2014-2891

    Last Modified: 12 Apr 2025

    strongSwan before 5.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a crafted ID_DER_ASN1_DN ID payload.

    Published: 5 May 2014
    3.3
    Low

    CVE-2014-3422

    Last Modified: 12 Apr 2025

    lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.

    Published: 5 May 2014
    3.3
    Low

    CVE-2014-3423

    Last Modified: 12 Apr 2025

    lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.

    Published: 5 May 2014
    3.3
    Low

    CVE-2014-3424

    Last Modified: 12 Apr 2025

    lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.

    Published: 5 May 2014
    5.8
    Medium

    CVE-2014-0116

    Last Modified: 12 Apr 2025

    CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and modify session state via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0113.

    Published: 5 May 2014
    3.3
    Low

    CVE-2014-3421

    Last Modified: 12 Apr 2025

    lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.

    Published: 5 May 2014
    4.9
    Medium

    CVE-2014-5339

    Last Modified: 12 Apr 2025

    Check_MK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write check_mk config files (.mk files) to arbitrary locations via vectors related to row selections.

    Published: 5 May 2014
    2.1
    Low

    CVE-2014-3209

    Last Modified: 12 Apr 2025

    The ldns-keygen tool in ldns 1.6.x uses the current umask to set the privileges of the private key, which might allow local users to obtain the private key by reading the file.

    Published: 3 May 2014
    7.8
    High

    CVE-2014-3000

    Last Modified: 12 Apr 2025

    The TCP reassembly function in the inet module in FreeBSD 8.3 before p16, 8.4 before p9, 9.1 before p12, 9.2 before p5, and 10.0 before p2 allows remote attackers to cause a denial of service (undefined memory access and system crash) or possibly read system memory via multiple crafted packets, related to moving a reassemble queue entry to the segment list when the queue is full.

    Published: 2 May 2014
    6.9
    Medium

    CVE-2014-2905

    Last Modified: 12 Apr 2025

    fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions.

    Published: 2 May 2014
    6.8
    Medium

    CVE-2014-3006

    Last Modified: 12 Apr 2025

    Sitepark Information Enterprise Server (IES) 2.9 before 2.9.6, when upgraded from an earlier version, does not properly restrict access, which allows remote attackers to change the manager account password and obtain sensitive information via a request to install/.

    Published: 2 May 2014
    7.5
    High

    CVE-2014-2322

    Last Modified: 12 Apr 2025

    lib/string_utf_support.rb in the Arabic Prawn 0.0.1 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) downloaded_file or (2) url variable.

    Published: 2 May 2014
    5.8
    Medium

    CVE-2014-3001

    Last Modified: 12 Apr 2025

    The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to bypass intended restrictions by leveraging a jailed device node process.

    Published: 2 May 2014
    4.3
    Medium

    CVE-2014-1899

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Citrix NetScaler Gateway (formerly Citrix Access Gateway Enterprise Edition) 9.x before 9.3.66.5 and 10.x before 10.1.123.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2158

    Last Modified: 12 Apr 2025

    Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45720.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2166

    Last Modified: 12 Apr 2025

    The SIP implementation in Cisco TelePresence TC Software 4.x and TE Software 4.x allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCto70562.

    Published: 2 May 2014
    9
    Critical

    CVE-2014-2169

    Last Modified: 12 Apr 2025

    Cisco TelePresence TC Software 4.x through 6.x before 6.2.0 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to internal system scripts, aka Bug ID CSCue60211.

    Published: 2 May 2014
    6
    Medium

    CVE-2014-1989

    Last Modified: 12 Apr 2025

    Cybozu Garoon 3.0 through 3.7 SP3 allows remote authenticated users to bypass intended access restrictions and delete schedule information via unspecified API calls.

    Published: 2 May 2014
    3.5
    Low

    CVE-2014-1988

    Last Modified: 12 Apr 2025

    The Phone Messages feature in Cybozu Garoon 2.0.0 through 3.7 SP2 allows remote authenticated users to cause a denial of service (resource consumption) via unspecified vectors.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2161

    Last Modified: 12 Apr 2025

    The H.225 subsystem in Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCty45731.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2162

    Last Modified: 12 Apr 2025

    The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCud29566.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2163

    Last Modified: 12 Apr 2025

    The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCua64961.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2164

    Last Modified: 12 Apr 2025

    The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCuj94651.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2165

    Last Modified: 12 Apr 2025

    The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCtq72699.

    Published: 2 May 2014
    7.6
    High

    CVE-2014-2168

    Last Modified: 12 Apr 2025

    Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to execute arbitrary code via crafted DNS response packets, aka Bug ID CSCty44804.

    Published: 2 May 2014
    10
    Critical

    CVE-2014-2171

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Cisco TelePresence TC Software 4.x through 6.x before 6.0.1 and TE Software 4.x and 6.0.x before 6.0.2 allows remote attackers to execute arbitrary code via crafted SIP packets, aka Bug ID CSCud81796.

    Published: 2 May 2014
    6.6
    Medium

    CVE-2014-2172

    Last Modified: 12 Apr 2025

    Buffer overflow in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows local users to gain privileges by leveraging improper handling of the u-boot compiler flag for internal executable files, aka Bug ID CSCub67693.

    Published: 2 May 2014
    7.2
    High

    CVE-2014-2173

    Last Modified: 12 Apr 2025

    Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 do not properly restrict access to the serial port, which allows local users to gain privileges via unspecified commands, aka Bug ID CSCub67692.

    Published: 2 May 2014
    7.1
    High

    CVE-2014-2156

    Last Modified: 12 Apr 2025

    Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45739.

    Published: 2 May 2014
    7.1
    High

    CVE-2014-2157

    Last Modified: 12 Apr 2025

    Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCty45733.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2159

    Last Modified: 12 Apr 2025

    The H.225 subsystem in Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCtq78722.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2160

    Last Modified: 12 Apr 2025

    The H.225 subsystem in Cisco TelePresence System MXP Series Software before F9.3.1 allows remote attackers to cause a denial of service (device reload) via crafted packets, aka Bug ID CSCty45745.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2167

    Last Modified: 12 Apr 2025

    The SIP implementation in Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allows remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCua86589.

    Published: 2 May 2014
    9
    Critical

    CVE-2014-2170

    Last Modified: 12 Apr 2025

    Cisco TelePresence TC Software 4.x and 5.x before 5.1.7 and 6.x before 6.0.1 and TE Software 4.x and 6.0 allow remote authenticated users to execute arbitrary commands by using the commands as arguments to tshell (aka tcsh) scripts, aka Bug ID CSCue60202.

    Published: 2 May 2014
    7.8
    High

    CVE-2014-2175

    Last Modified: 12 Apr 2025

    Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 allow remote attackers to cause a denial of service (memory consumption) via crafted H.225 packets, aka Bug ID CSCtq78849.

    Published: 2 May 2014
    7.5
    High

    CVE-2014-3139

    Last Modified: 12 Apr 2025

    recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to a certain string.

    Published: 2 May 2014
    4.3
    Medium

    CVE-2013-2073

    Last Modified: 12 Apr 2025

    Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate.

    Published: 2 May 2014
    4.3
    Medium

    CVE-2014-1441

    Last Modified: 12 Apr 2025

    Core FTP Server 1.2 before build 515 allows remote attackers to cause a denial of service (reachable assertion and crash) via an AUTH SSL command with malformed data, as demonstrated by pressing the enter key twice.

    Published: 2 May 2014
    4
    Medium

    CVE-2014-1442

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Core FTP Server 1.2 before build 515 allows remote authenticated users to determine the existence of arbitrary files via a /../ sequence in an XCRC command.

    Published: 2 May 2014
    4
    Medium

    CVE-2014-1443

    Last Modified: 12 Apr 2025

    Core FTP Server 1.2 before build 515 allows remote authenticated users to obtain sensitive information (password for the previous user) via a USER command with a specific length, possibly related to an out-of-bounds read.

    Published: 2 May 2014
    4.3
    Medium

    CVE-2013-7110

    Last Modified: 12 Apr 2025

    Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2073.

    Published: 2 May 2014
    4
    Medium

    CVE-2014-5356

    Last Modified: 12 Apr 2025

    OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.

    Published: 2 May 2014
    6.5
    Medium

    CVE-2014-3138

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Xerox DocuShare before 6.53 Patch 6 Hotfix 2, 6.6.1 Update 1 before Hotfix 24, and 6.6.1 Update 2 before Hotfix 3 allows remote authenticated users to execute arbitrary SQL commands via the PATH_INFO to /docushare/dsweb/ResultBackgroundJobMultiple/. NOTE: some of these details are obtained from third party information.

    Published: 2 May 2014
    6.9
    Medium

    CVE-2014-0646

    Last Modified: 12 Apr 2025

    The runtime WS component in the server in EMC RSA Access Manager 6.1.3 before 6.1.3.39, 6.1.4 before 6.1.4.22, 6.2.0 before 6.2.0.11, and 6.2.1 before 6.2.1.03, when INFO logging is enabled, allows local users to discover cleartext passwords by reading log files.

    Published: 1 May 2014
    3.5
    Low

    CVE-2014-0941

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0942.

    Published: 1 May 2014
    3.5
    Low

    CVE-2013-6323

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, and WebSphere Virtual Enterprise 7.x before 7.0.0.5, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 1 May 2014
    4.3
    Medium

    CVE-2014-0823

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote attackers to read arbitrary files via a crafted URL.

    Published: 1 May 2014