CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2013-7064

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance popup" permission to inject arbitrary web script or HTML via unspecified configuration values.

    Published: 29 Apr 2014
    5.8
    Medium

    CVE-2013-7065

    Last Modified: 12 Apr 2025

    The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions and post to arbitrary groups via a group audience field, as demonstrated by the og_group_ref field.

    Published: 29 Apr 2014
    4.3
    Medium

    CVE-2013-7066

    Last Modified: 12 Apr 2025

    The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal allows remote attackers to read private nodes titles by leveraging edit permissions to a node that references a private node.

    Published: 29 Apr 2014
    7.5
    High

    CVE-2013-7134

    Last Modified: 12 Apr 2025

    Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cookies.

    Published: 29 Apr 2014
    5
    Medium

    CVE-2013-7111

    Last Modified: 12 Apr 2025

    The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on the command line, which allows remote attackers to obtain sensitive information by listing the processes.

    Published: 29 Apr 2014
    4.3
    Medium

    CVE-2013-7234

    Last Modified: 12 Apr 2025

    Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header.

    Published: 29 Apr 2014
    7.5
    High

    CVE-2013-7235

    Last Modified: 12 Apr 2025

    Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space characters characters.

    Published: 29 Apr 2014
    7.5
    High

    CVE-2013-7236

    Last Modified: 12 Apr 2025

    Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username.

    Published: 29 Apr 2014
    6.8
    Medium

    CVE-2013-7302

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.

    Published: 29 Apr 2014
    4.9
    Medium

    CVE-2013-7068

    Last Modified: 12 Apr 2025

    The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field.

    Published: 29 Apr 2014
    6.8
    Medium

    CVE-2013-7259

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary code, as demonstrated by a request to (1) db/data/ext/GremlinPlugin/graphdb/execute_script or (2) db/manage/server/console/.

    Published: 29 Apr 2014
    6.1
    Medium

    CVE-2014-2182

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software, when DHCPv6 replay is configured, allows remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 packet, aka Bug ID CSCun45520.

    Published: 29 Apr 2014
    6.3
    Medium

    CVE-2014-2183

    Last Modified: 12 Apr 2025

    The L2TP module in Cisco IOS XE 3.10S(.2) and earlier on ASR 1000 routers allows remote authenticated users to cause a denial of service (ESP card reload) via a malformed L2TP packet, aka Bug ID CSCun09973.

    Published: 29 Apr 2014
    5
    Medium

    CVE-2014-1841

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's home folder via a Move action with a .. (dot dot) in the src parameter.

    Published: 29 Apr 2014
    5
    Medium

    CVE-2014-1842

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to list all usernames via a Go action with a .. (dot dot) in the search-bar value.

    Published: 29 Apr 2014
    5
    Medium

    CVE-2014-1843

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to obtain the property information of an arbitrary home folder via a Properties action with a .. (dot dot) in the src parameter.

    Published: 29 Apr 2014
    4
    Medium

    CVE-2014-2180

    Last Modified: 12 Apr 2025

    The Document Management component in Cisco Unified Contact Center Express does not properly validate a parameter, which allows remote authenticated users to upload files to arbitrary pathnames via a crafted HTTP request, aka Bug ID CSCun74133.

    Published: 29 Apr 2014
    4
    Medium

    CVE-2014-2185

    Last Modified: 12 Apr 2025

    The Call Detail Records (CDR) Management component in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to obtain sensitive information by reading extraneous fields in an HTML document, aka Bug ID CSCun74374.

    Published: 29 Apr 2014
    5
    Medium

    CVE-2014-2184

    Last Modified: 12 Apr 2025

    The IP Manager Assistant (IPMA) component in Cisco Unified Communications Manager (Unified CM) allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCun74352.

    Published: 29 Apr 2014
    9.8
    Critical

    CVE-2014-1532

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resolution.

    Published: 29 Apr 2014
    8.8
    High

    CVE-2014-1531

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving an imgLoader object that is not properly handled during an image-resize operation.

    Published: 29 Apr 2014
    6.1
    Medium

    CVE-2014-1530

    Last Modified: 25 Nov 2025

    The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.

    Published: 29 Apr 2014
    8.8
    High

    CVE-2014-1529

    Last Modified: 25 Nov 2025

    The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted.

    Published: 29 Apr 2014
    6.5
    Medium

    CVE-2014-1523

    Last Modified: 25 Nov 2025

    Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.

    Published: 29 Apr 2014
    7.5
    High

    CVE-2014-0114

    Last Modified: 12 Apr 2025

    Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, as demonstrated by the passing of this parameter to the getClass method of the ActionForm object in Struts 1.

    Published: 29 Apr 2014
    6.8
    Medium

    CVE-2014-0168

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a crafted web page.

    Published: 29 Apr 2014
    9.3
    Critical

    CVE-2014-1522

    Last Modified: 12 Apr 2025

    The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via crafted content.

    Published: 29 Apr 2014
    9.3
    Critical

    CVE-2014-1525

    Last Modified: 12 Apr 2025

    The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) via a crafted VIDEO element in an HTML document.

    Published: 29 Apr 2014
    6.7
    Medium

    CVE-2014-3124

    Last Modified: 12 Apr 2025

    The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.

    Published: 29 Apr 2014
    8.8
    High

    CVE-2014-1518

    Last Modified: 25 Nov 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 29 Apr 2014
    9.8
    Critical

    CVE-2014-1524

    Last Modified: 25 Nov 2025

    The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted JavaScript code that accesses a non-XBL object as if it were an XBL object.

    Published: 29 Apr 2014
    6.8
    Medium

    CVE-2014-1526

    Last Modified: 12 Apr 2025

    The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.

    Published: 29 Apr 2014
    10
    Critical

    CVE-2014-1528

    Last Modified: 12 Apr 2025

    The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.

    Published: 29 Apr 2014
    2.1
    Low

    CVE-2013-4285

    Last Modified: 12 Apr 2025

    A certain Gentoo patch for the PAM S/Key module does not properly clear credentials from memory, which allows local users to obtain sensitive information by reading system memory.

    Published: 28 Apr 2014
    7.5
    High

    CVE-2014-2657

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the print release functionality in PaperCut MF before 14.1 (Build 26983) has unknown impact and remote vectors, related to embedded MFPs.

    Published: 28 Apr 2014
    10
    Critical

    CVE-2014-3008

    Last Modified: 12 Apr 2025

    Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the comm parameter to recoveryconsole/bpl/snmpd.php.

    Published: 28 Apr 2014
    5
    Medium

    CVE-2014-0037

    Last Modified: 12 Apr 2025

    The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 5.00 before 7.1.8 beta2 allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the username."

    Published: 28 Apr 2014
    5
    Medium

    CVE-2014-0079

    Last Modified: 12 Apr 2025

    The ValidateUserLogon function in provider/libserver/ECSession.cpp in Zarafa 7.1.8, 6.20.0, and earlier, when using certain build conditions, allows remote attackers to cause a denial of service (crash) via vectors related to "a NULL pointer of the password."

    Published: 28 Apr 2014
    7.5
    High

    CVE-2014-1217

    Last Modified: 12 Apr 2025

    Livetecs Timelive before 6.2.8 does not properly restrict access to systemsetting.aspx, which allows remote attackers to change configurations and obtain the database connection string and credentials via unspecified vectors.

    Published: 28 Apr 2014
    7.5
    High

    CVE-2014-2042

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the Manage Project functionality in Livetecs Timelive before 6.5.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a predictable directory in Uploads/.

    Published: 28 Apr 2014
    4.3
    Medium

    CVE-2014-2715

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in vwrooms\templates\logout.tpl.php in the VideoWhisper Webcam plugins for Drupal 7.x allow remote attackers to inject arbitrary web script or HTML via the (1) module or (2) message parameter to index.php.

    Published: 28 Apr 2014
    5
    Medium

    CVE-2014-2658

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Papercut MF and NG before 14.1 (Build 26983) allows attacker to cause a denial of service via unknown vectors.

    Published: 28 Apr 2014
    7.5
    High

    CVE-2014-2846

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.

    Published: 28 Apr 2014
    4.3
    Medium

    CVE-2014-2980

    Last Modified: 12 Apr 2025

    Tools/gdomap.c in gdomap in GNUstep Base 1.24.6 and earlier, when run in daemon mode, does not properly handle the file descriptor for the logger, which allows remote attackers to cause a denial of service (abort) via an invalid request.

    Published: 28 Apr 2014
    5.5
    Medium

    CVE-2014-2986

    Last Modified: 12 Apr 2025

    The vgic_distr_mmio_write function in the virtual guest interrupt controller (GIC) distributor (arch/arm/vgic.c) in Xen 4.4.x, when running on an ARM system, allows local guest users to cause a denial of service (NULL pointer dereference and host crash) via unspecified vectors.

    Published: 28 Apr 2014
    6.8
    Medium

    CVE-2014-2383

    Last Modified: 12 Apr 2025

    dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.

    Published: 28 Apr 2014
    5
    Medium

    CVE-2013-6445

    Last Modified: 12 Apr 2025

    Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier for attackers to obtain sensitive information via a brute-force attack.

    Published: 28 Apr 2014
    10
    Critical

    CVE-2014-0515

    Last Modified: 12 Apr 2025

    Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before 11.2.202.356 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in April 2014.

    Published: 28 Apr 2014
    Unknown

    CVE-2013-4336

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5964. Reason: This candidate is a duplicate of CVE-2013-5964. Notes: All CVE users should reference CVE-2013-5964 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Apr 2014
    Unknown

    CVE-2012-3415

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-2401. Reason: This candidate is a duplicate of CVE-2012-2401. Notes: All CVE users should reference CVE-2012-2401 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Apr 2014