CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2014-0857

    Last Modified: 12 Apr 2025

    The Administrative Console in IBM WebSphere Application Server (WAS) 8.x before 8.0.0.9 and 8.5.x before 8.5.5.2 allows remote authenticated users to obtain sensitive information via a crafted request.

    Published: 1 May 2014
    5
    Medium

    CVE-2014-0859

    Last Modified: 12 Apr 2025

    The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

    Published: 1 May 2014
    4.3
    Medium

    CVE-2014-0896

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) Liberty Profile 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information via a crafted request.

    Published: 1 May 2014
    3.5
    Low

    CVE-2014-0942

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0941.

    Published: 1 May 2014
    10
    Critical

    CVE-2014-2881

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Diffie-Hellman key agreement implementation in the management GUI Java applet in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unknown impact and vectors.

    Published: 1 May 2014
    4.6
    Medium

    CVE-2013-7374

    Last Modified: 12 Apr 2025

    The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypass the greeter screen restrictions by clicking the date.

    Published: 1 May 2014
    10
    Critical

    CVE-2014-2882

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the management GUI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 9.3-66.5 and 10.x before 10.1-122.17 has unspecified impact and vectors, related to certificate validation.

    Published: 1 May 2014
    Unknown

    CVE-2013-4121

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was a site-specific issue. Notes: none

    Published: 1 May 2014
    7.5
    High

    CVE-2014-0786

    Last Modified: 13 Oct 2025

    Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverage the guest role.

    Published: 1 May 2014
    5.5
    Medium

    CVE-2014-0196

    Last Modified: 21 Apr 2026

    The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

    Published: 1 May 2014
    4.3
    Medium

    CVE-2014-0034

    Last Modified: 12 Apr 2025

    The SecurityTokenService (STS) in Apache CXF before 2.6.12 and 2.7.x before 2.7.9 does not properly validate SAML tokens when caching is enabled, which allows remote attackers to gain access via an invalid SAML token.

    Published: 1 May 2014
    4.3
    Medium

    CVE-2014-0035

    Last Modified: 12 Apr 2025

    The SymmetricBinding in Apache CXF before 2.6.13 and 2.7.x before 2.7.10, when EncryptBeforeSigning is enabled and the UsernameToken policy is set to an EncryptedSupportingToken, transmits the UsernameToken in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 1 May 2014
    2.1
    Low

    CVE-2014-0164

    Last Modified: 12 Apr 2025

    openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.

    Published: 1 May 2014
    7.5
    High

    CVE-2014-3540

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0114. Reason: This candidate is a duplicate of CVE-2014-0114. CVE abstraction content decisions did not require a second ID. Notes: All CVE users should reference CVE-2014-0114 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 May 2014
    4.3
    Medium

    CVE-2014-0110

    Last Modified: 12 Apr 2025

    Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message.

    Published: 1 May 2014
    4.3
    Medium

    CVE-2014-0109

    Last Modified: 12 Apr 2025

    Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (memory consumption) via a large request with the Content-Type set to text/html to a SOAP endpoint, which triggers an error.

    Published: 1 May 2014
    4.3
    Medium

    CVE-2014-0149

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Red Hat JBoss Web Framework Kit 2.5.0 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter or (2) id name.

    Published: 1 May 2014
    5
    Medium

    CVE-2014-0193

    Last Modified: 12 Apr 2025

    WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames.

    Published: 1 May 2014
    5.9
    Medium

    CVE-2014-3230

    Last Modified: 21 Nov 2024

    The libwww-perl LWP::Protocol::https module 6.04 through 6.06 for Perl, when using IO::Socket::SSL as the SSL socket class, allows attackers to disable server certificate validation via the (1) HTTPS_CA_DIR or (2) HTTPS_CA_FILE environment variable.

    Published: 1 May 2014
    3.5
    Low

    CVE-2014-2260

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in plugins/main/content/js/ajenti.coffee in Eugene Pankov Ajenti 1.2.13 allows remote authenticated users to inject arbitrary web script or HTML via the command field in the Cron functionality.

    Published: 30 Apr 2014
    Unknown

    CVE-2013-1805

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1806. Reason: This issue was MERGED into CVE-2013-1806 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2013-1806 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Apr 2014
    6.5
    Medium

    CVE-2013-1806

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to administration/user_fields.php or (3) file parameter to administration/db_backup.php.

    Published: 30 Apr 2014
    5
    Medium

    CVE-2013-1807

    Last Modified: 12 Apr 2025

    PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.

    Published: 30 Apr 2014
    9
    Critical

    CVE-2013-6990

    Last Modified: 12 Apr 2025

    FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.

    Published: 30 Apr 2014
    5
    Medium

    CVE-2014-0471

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted source package, related to "C-style filename quoting."

    Published: 30 Apr 2014
    4.3
    Medium

    CVE-2014-3135

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 5.1.1 Alpha 9 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to privatemessage/new/, (2) the folderid parameter to a private message in privatemessage/view, (3) a fragment indicator to /help, or (4) the view parameter to a topic, as demonstrated by a request to forum/anunturi-importante/rst-power/67030-rst-admin-restore.

    Published: 30 Apr 2014
    5
    Medium

    CVE-2014-3129

    Last Modified: 12 Apr 2025

    The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted request, related to SAP Solution Manager 7.1.

    Published: 30 Apr 2014
    4.6
    Medium

    CVE-2014-3130

    Last Modified: 12 Apr 2025

    The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does not properly restrict access, which allows local users to gain privileges and execute ABAP instructions via crafted help messages.

    Published: 30 Apr 2014
    4
    Medium

    CVE-2014-3131

    Last Modified: 12 Apr 2025

    SAP Profile Maintenance does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1.

    Published: 30 Apr 2014
    4
    Medium

    CVE-2014-3132

    Last Modified: 12 Apr 2025

    SAP Background Processing does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1.

    Published: 30 Apr 2014
    5
    Medium

    CVE-2014-3133

    Last Modified: 12 Apr 2025

    SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered on an SLD via an unspecified webdynpro, related to SystemSelection.

    Published: 30 Apr 2014
    4.3
    Medium

    CVE-2014-3134

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the InfoView application in SAP BusinessObjects allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Apr 2014
    4.3
    Medium

    CVE-2014-1955

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Apr 2014
    5
    Medium

    CVE-2014-1956

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 30 Apr 2014
    6.5
    Medium

    CVE-2014-1957

    Last Modified: 12 Apr 2025

    FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 30 Apr 2014
    6.5
    Medium

    CVE-2014-2565

    Last Modified: 12 Apr 2025

    The commandline interface in Blue Coat Content Analysis System (CAS) 1.1 before 1.1.4.2 allows remote administrators to execute arbitrary commands via unspecified vectors, related to "command injection."

    Published: 30 Apr 2014
    7.2
    High

    CVE-2014-0470

    Last Modified: 12 Apr 2025

    super.c in Super 3.30.0 does not check the return value of the setuid function when the -F flag is set, which allows local users to gain privileges via unspecified vectors, aka an RLIMIT_NPROC attack.

    Published: 30 Apr 2014
    6.9
    Medium

    CVE-2014-1520

    Last Modified: 25 Nov 2025

    maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.

    Published: 30 Apr 2014
    9.3
    Critical

    CVE-2014-1519

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 30 Apr 2014
    6.8
    Medium

    CVE-2014-2186

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj81777.

    Published: 30 Apr 2014
    5
    Medium

    CVE-2014-2545

    Last Modified: 12 Apr 2025

    TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before 1.0.1 allow remote attackers to obtain sensitive information via a crafted HTTP request.

    Published: 30 Apr 2014
    5
    Medium

    CVE-2014-1527

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.

    Published: 30 Apr 2014
    7.2
    High

    CVE-2014-0185

    Last Modified: 12 Apr 2025

    sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.

    Published: 30 Apr 2014
    2.1
    Low

    CVE-2014-1739

    Last Modified: 12 Apr 2025

    The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read access for a MEDIA_IOC_ENUM_ENTITIES ioctl call.

    Published: 30 Apr 2014
    6.2
    Medium

    CVE-2014-3125

    Last Modified: 12 Apr 2025

    Xen 4.4.x, when running on an ARM system, does not properly context switch the CNTKCTL_EL1 register, which allows local guest users to modify the hardware timers and cause a denial of service (crash) via unspecified vectors.

    Published: 30 Apr 2014
    5
    Medium

    CVE-2013-7372

    Last Modified: 12 Apr 2025

    The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache Harmony through 6.0M3, as used in the Java Cryptography Architecture (JCA) in Android before 4.4 and other products, when no seed is provided by the user, uses an incorrect offset value, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging the resulting PRNG predictability, as exploited in the wild against Bitcoin wallet applications in August 2013.

    Published: 29 Apr 2014
    4.3
    Medium

    CVE-2013-1804

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php; or remote authenticated users with certain permissions to inject arbitrary web script or HTML via the (2) user_list or (3) user_types parameter to messages.php; (4) message parameter to infusions/shoutbox_panel/shoutbox_admin.php; (5) message parameter to administration/news.php; (6) panel_list parameter to administration/panel_editor.php; (7) HTTP User Agent string to administration/phpinfo.php; (8) "__BBCODE__" parameter to administration/bbcodes.php; errorMessage parameter to (9) article_cats.php, (10) download_cats.php, (11) news_cats.php, or (12) weblink_cats.php in administration/, when error is 3; or (13) body or (14) body2 parameter to administration/articles.php.

    Published: 29 Apr 2014
    7.5
    High

    CVE-2013-7373

    Last Modified: 12 Apr 2025

    Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within multiple applications.

    Published: 29 Apr 2014
    4.3
    Medium

    CVE-2014-2853

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in includes/actions/InfoAction.php in MediaWiki before 1.21.9 and 1.22.x before 1.22.6 allows remote attackers to inject arbitrary web script or HTML via the sort key in an info action.

    Published: 29 Apr 2014
    5
    Medium

    CVE-2013-7063

    Last Modified: 12 Apr 2025

    The Invitation module 7.x-2.x for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via unspecified default views.

    Published: 29 Apr 2014