CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-5279

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a \n (newline) character in an HTTP header.

    Published: 23 Apr 2014
    Unknown

    CVE-2014-0360

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2741. Reason: This candidate is a duplicate of CVE-2014-2741. Notes: All CVE users should reference CVE-2014-2741 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Apr 2014
    5
    Medium

    CVE-2014-0892

    Last Modified: 12 Apr 2025

    IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W.

    Published: 23 Apr 2014
    2.6
    Low

    CVE-2014-1646

    Last Modified: 12 Apr 2025

    Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform memory copies, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate.

    Published: 23 Apr 2014
    2.6
    Low

    CVE-2014-1647

    Last Modified: 12 Apr 2025

    Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform block-data moves, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate.

    Published: 23 Apr 2014
    7.5
    High

    CVE-2014-2888

    Last Modified: 12 Apr 2025

    lib/sfpagent/bsig.rb in the sfpagent gem before 0.4.15 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the module name in a JSON request.

    Published: 23 Apr 2014
    6.8
    Medium

    CVE-2014-2327

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.

    Published: 23 Apr 2014
    6.5
    Medium

    CVE-2014-2328

    Last Modified: 12 Apr 2025

    lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors.

    Published: 23 Apr 2014
    5
    Medium

    CVE-2014-2976

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request to TCP port 18081.

    Published: 23 Apr 2014
    7.5
    High

    CVE-2014-2709

    Last Modified: 12 Apr 2025

    lib/rrd.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified parameters.

    Published: 23 Apr 2014
    4.3
    Medium

    CVE-2014-2554

    Last Modified: 12 Apr 2025

    OTRS 3.1.x before 3.1.21, 3.2.x before 3.2.16, and 3.3.x before 3.3.6 allows remote attackers to conduct clickjacking attacks via an IFRAME element.

    Published: 23 Apr 2014
    5
    Medium

    CVE-2014-2983

    Last Modified: 12 Apr 2025

    Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous users to obtain sensitive interim form input information in opportunistic situations via unspecified vectors.

    Published: 23 Apr 2014
    10
    Critical

    CVE-2014-1314

    Last Modified: 12 Apr 2025

    WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox protection mechanism and execute arbitrary code via a crafted application.

    Published: 23 Apr 2014
    4.9
    Medium

    CVE-2014-1320

    Last Modified: 12 Apr 2025

    IOKit in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 places kernel pointers into an object data structure, which makes it easier for local users to bypass the ASLR protection mechanism by reading unspecified attributes of the object.

    Published: 23 Apr 2014
    6.8
    Medium

    CVE-2012-5036

    Last Modified: 12 Apr 2025

    Cisco IOS before 12.2(50)SY1 allows remote authenticated users to cause a denial of service (memory consumption) via a sequence of VTY management sessions (aka exec sessions), aka Bug ID CSCtn43662.

    Published: 23 Apr 2014
    5
    Medium

    CVE-2012-0360

    Last Modified: 12 Apr 2025

    Memory leak in Cisco IOS before 15.1(1)SY, when IKEv2 debugging is enabled, allows remote attackers to cause a denial of service (memory consumption) via crafted packets, aka Bug ID CSCtn22376.

    Published: 23 Apr 2014
    5.4
    Medium

    CVE-2012-1317

    Last Modified: 12 Apr 2025

    The multicast implementation in Cisco IOS before 15.1(1)SY allows remote attackers to cause a denial of service (Route Processor crash) by sending packets at a high rate, aka Bug ID CSCts37717.

    Published: 23 Apr 2014
    5.7
    Medium

    CVE-2012-3062

    Last Modified: 12 Apr 2025

    Cisco IOS before 15.1(1)SY, when Multicast Listener Discovery (MLD) snooping is enabled, allows remote attackers to cause a denial of service (CPU consumption or device crash) via MLD packets on a network that contains many IPv6 hosts, aka Bug ID CSCtr88193.

    Published: 23 Apr 2014
    4.3
    Medium

    CVE-2012-3918

    Last Modified: 12 Apr 2025

    Cisco IOS before 15.3(1)T on Cisco 2900 devices, when a VWIC2-2MFT-T1/E1 card is configured for TDM/HDLC mode, allows remote attackers to cause a denial of service (serial-interface outage) via certain Frame Relay traffic, aka Bug ID CSCub13317.

    Published: 23 Apr 2014
    4.9
    Medium

    CVE-2012-4638

    Last Modified: 12 Apr 2025

    Cisco IOS before 15.1(1)SY allows local users to cause a denial of service (device reload) by establishing an outbound SSH session, aka Bug ID CSCto00318.

    Published: 23 Apr 2014
    4.3
    Medium

    CVE-2012-4651

    Last Modified: 12 Apr 2025

    Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets from the Scan Safe Tower, aka Bug ID CSCub85451.

    Published: 23 Apr 2014
    6.3
    Medium

    CVE-2012-5014

    Last Modified: 12 Apr 2025

    Cisco IOS before 15.1(2)SY allows remote authenticated users to cause a denial of service (device crash) by establishing an SSH session from a client and then placing this client into a (1) slow or (2) idle state, aka Bug ID CSCto87436.

    Published: 23 Apr 2014
    6.8
    Medium

    CVE-2012-5017

    Last Modified: 12 Apr 2025

    Cisco IOS before 15.1(1)SY1 allows remote authenticated users to cause a denial of service (device reload) by establishing a VPN session and then sending malformed IKEv2 packets, aka Bug ID CSCub39268.

    Published: 23 Apr 2014
    4.3
    Medium

    CVE-2012-5039

    Last Modified: 12 Apr 2025

    The BGP Router process in Cisco IOS before 12.2(50)SY1 allows remote attackers to cause a denial of service (memory consumption) via vectors involving BGP path attributes, aka Bug ID CSCsw63003.

    Published: 23 Apr 2014
    5.4
    Medium

    CVE-2012-5044

    Last Modified: 12 Apr 2025

    Cisco IOS before 15.3(1)T, when media flow-around is not used, allows remote attackers to cause a denial of service (media loops and stack memory corruption) via VoIP traffic, aka Bug ID CSCub45809.

    Published: 23 Apr 2014
    6.8
    Medium

    CVE-2012-5422

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Cisco IOS before 15.3(2)T on AS5400 devices allows remote authenticated users to cause a denial of service (spurious errors) via unknown vectors, aka Bug ID CSCub61009.

    Published: 23 Apr 2014
    4
    Medium

    CVE-2012-5427

    Last Modified: 12 Apr 2025

    Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug ID CSCuc42518.

    Published: 23 Apr 2014
    4.3
    Medium

    CVE-2014-1296

    Last Modified: 12 Apr 2025

    CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during transmission of a header, as demonstrated by an HTTPOnly restriction.

    Published: 23 Apr 2014
    6.8
    Medium

    CVE-2014-1315

    Last Modified: 12 Apr 2025

    Format string vulnerability in CoreServicesUIAgent in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a URL.

    Published: 23 Apr 2014
    5
    Medium

    CVE-2014-1316

    Last Modified: 12 Apr 2025

    Heimdal, as used in Apple OS X through 10.9.2, allows remote attackers to cause a denial of service (abort and daemon exit) via ASN.1 data encountered in the Kerberos 5 protocol.

    Published: 23 Apr 2014
    10
    Critical

    CVE-2014-1318

    Last Modified: 12 Apr 2025

    The Intel Graphics Driver in Apple OS X through 10.9.2 does not properly validate a certain pointer, which allows attackers to execute arbitrary code via a crafted application.

    Published: 23 Apr 2014
    6.8
    Medium

    CVE-2014-1319

    Last Modified: 12 Apr 2025

    Buffer overflow in ImageIO in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.

    Published: 23 Apr 2014
    4.9
    Medium

    CVE-2014-1322

    Last Modified: 12 Apr 2025

    The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user space, which makes it easier for local users to bypass the ASLR protection mechanism by reading an unspecified attribute of the object.

    Published: 23 Apr 2014
    4.3
    Medium

    CVE-2014-1648

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary web script or HTML via the displayTab parameter.

    Published: 23 Apr 2014
    5
    Medium

    CVE-2014-2154

    Last Modified: 12 Apr 2025

    Memory leak in the SIP inspection engine in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (memory consumption and instability) via crafted SIP packets, aka Bug ID CSCuf67469.

    Published: 23 Apr 2014
    5
    Medium

    CVE-2012-4658

    Last Modified: 12 Apr 2025

    The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage) via vectors that trigger incorrectly terminated HTTP sessions, aka Bug ID CSCtz99447.

    Published: 23 Apr 2014
    6.8
    Medium

    CVE-2014-1295

    Last Modified: 12 Apr 2025

    Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack."

    Published: 23 Apr 2014
    3.3
    Low

    CVE-2014-1321

    Last Modified: 12 Apr 2025

    Power Management in Apple OS X 10.9.x through 10.9.2 allows physically proximate attackers to bypass an intended transition into the locked-screen state by touching (1) a key or (2) the trackpad during a lid-close action.

    Published: 23 Apr 2014
    6.1
    Medium

    CVE-2012-1366

    Last Modified: 12 Apr 2025

    Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544.

    Published: 23 Apr 2014
    6.4
    Medium

    CVE-2012-5032

    Last Modified: 12 Apr 2025

    The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows remote attackers to trigger the forwarding of VPN traffic to an attacker-controlled destination, or the discarding of this traffic, by arranging for an arbitrary device to become a cluster member, aka Bug ID CSCub93641.

    Published: 23 Apr 2014
    4.6
    Medium

    CVE-2012-5037

    Last Modified: 12 Apr 2025

    The ACL implementation in Cisco IOS before 15.1(1)SY on Catalyst 6500 and 7600 devices allows local users to cause a denial of service (device reload) via a "no object-group" command followed by an object-group command, aka Bug ID CSCts16133.

    Published: 23 Apr 2014
    7.5
    High

    CVE-2014-0188

    Last Modified: 12 Apr 2025

    The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

    Published: 23 Apr 2014
    2.1
    Low

    CVE-2014-0181

    Last Modified: 12 Apr 2025

    The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.

    Published: 23 Apr 2014
    5.8
    Medium

    CVE-2014-4336

    Last Modified: 12 Apr 2025

    The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.

    Published: 23 Apr 2014
    4.3
    Medium

    CVE-2014-4337

    Last Modified: 12 Apr 2025

    The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.

    Published: 23 Apr 2014
    3.5
    Low

    CVE-2014-3801

    Last Modified: 12 Apr 2025

    OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.

    Published: 23 Apr 2014
    4.3
    Medium

    CVE-2014-2890

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the wrap_html function in MyID.php in phpMyID 0.9 allows remote attackers to inject arbitrary web script or HTML via the openid_error parameter to MyID.config.php when the openid.mode parameter is set to error, which is not properly handled in an error message.

    Published: 22 Apr 2014
    7.5
    High

    CVE-2014-2892

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the get_answer function in mmsh.c in libmms before 0.6.4 allows remote attackers to execute arbitrary code via a long line in an MMS over HTTP (MMSH) server response.

    Published: 22 Apr 2014
    5
    Medium

    CVE-2014-2899

    Last Modified: 12 Apr 2025

    wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found.

    Published: 22 Apr 2014
    5.8
    Medium

    CVE-2014-2900

    Last Modified: 12 Apr 2025

    wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.

    Published: 22 Apr 2014