CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2014-2522

    Last Modified: 12 Apr 2025

    curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when accessing a URL that uses a numerical IP address, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.

    Published: 18 Apr 2014
    3.5
    Low

    CVE-2014-2287

    Last Modified: 12 Apr 2025

    channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote authenticated users to cause a denial of service (channel and file descriptor consumption) via an INVITE request with a (1) Session-Expires or (2) Min-SE header with a malformed or invalid value.

    Published: 18 Apr 2014
    4.3
    Medium

    CVE-2014-2288

    Last Modified: 12 Apr 2025

    The PJSIP channel driver in Asterisk Open Source 12.x before 12.1.1, when qualify_frequency "is enabled on an AOR and the remote SIP server challenges for authentication of the resulting OPTIONS request," allows remote attackers to cause a denial of service (crash) via a PJSIP endpoint that does not have an associated outgoing request.

    Published: 18 Apr 2014
    3.5
    Low

    CVE-2014-2289

    Last Modified: 12 Apr 2025

    res/res_pjsip_exten_state.c in the PJSIP channel driver in Asterisk Open Source 12.x before 12.1.0 allows remote authenticated users to cause a denial of service (crash) via a SUBSCRIBE request without any Accept headers, which triggers an invalid pointer dereference.

    Published: 18 Apr 2014
    4.3
    Medium

    CVE-2014-2014

    Last Modified: 12 Apr 2025

    imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain credentials by sniffing the network.

    Published: 18 Apr 2014
    4.9
    Medium

    CVE-2014-2597

    Last Modified: 12 Apr 2025

    PCNetSoftware RAC Server 4.0.4 and 4.0.5 allows local users to cause a denial of service (disabled keyboard or crash) via a large input buffer to unspecified IOCTL requests in RACDriver.sys, which triggers a buffer over-read.

    Published: 18 Apr 2014
    5
    Medium

    CVE-2013-4279

    Last Modified: 12 Apr 2025

    imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to the developer's site.

    Published: 18 Apr 2014
    7.5
    High

    CVE-2014-2286

    Last Modified: 12 Apr 2025

    main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consumption) and possibly execute arbitrary code via an HTTP request with a large number of Cookie headers.

    Published: 18 Apr 2014
    2.1
    Low

    CVE-2012-6646

    Last Modified: 12 Apr 2025

    F-Secure Anti-Virus, Safe Anywhere, and PSB Workstation Security before 11500 for Mac OS X allows local users to disable the Mac OS X firewall via unspecified vectors.

    Published: 18 Apr 2014
    6.3
    Medium

    CVE-2012-0871

    Last Modified: 12 Apr 2025

    The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.

    Published: 18 Apr 2014
    7.5
    High

    CVE-2013-7369

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Exchange Server before HF02, Anti-Virus for Windows Servers 9.00 before HF09, Anti-Virus for Citrix Servers 9.00 before HF09, and F-Secure Email and Server Security and F-Secure Server Security 9.20 before HF01 allows remote attackers to execute arbitrary SQL commands via unknown vectors, related to GetCommand.

    Published: 18 Apr 2014
    3.5
    Low

    CVE-2014-2844

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in F-Secure Messaging Secure Gateway 7.5.0 before Patch 1862 allows remote authenticated administrators to inject arbitrary web script or HTML via the new parameter in the SysUser module to admin.

    Published: 18 Apr 2014
    5.5
    Medium

    CVE-2014-4658

    Last Modified: 21 Nov 2024

    The vault subsystem in Ansible before 1.5.5 does not set the umask before creation or modification of a vault file, which allows local users to obtain sensitive key information by reading a file.

    Published: 18 Apr 2014
    4.3
    Medium

    CVE-2014-2391

    Last Modified: 12 Apr 2025

    The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potentially useful password-pattern information by reading (1) a web-server access log, (2) a web-server Referer log, or (3) browser history that contains this string because of its presence in a GET request.

    Published: 17 Apr 2014
    4.3
    Medium

    CVE-2014-2392

    Last Modified: 12 Apr 2025

    The E-Mail autoconfiguration feature in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 places a password in a GET request, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

    Published: 17 Apr 2014
    4.3
    Medium

    CVE-2014-2393

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite 7.4.1 before 7.4.1-rev11 and 7.4.2 before 7.4.2-rev13 allows remote attackers to inject arbitrary web script or HTML via a Drive filename that is not properly handled during use of the composer to add an e-mail attachment.

    Published: 17 Apr 2014
    6.5
    Medium

    CVE-2014-0111

    Last Modified: 12 Apr 2025

    Apache Syncope 1.0.0 before 1.0.9 and 1.1.0 before 1.1.7 allows remote administrators to execute arbitrary Java code via vectors related to Apache Commons JEXL expressions, "derived schema definition," "user / role templates," and "account links of resource mappings."

    Published: 17 Apr 2014
    5
    Medium

    CVE-2014-2469

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in lighttpd in Oracle Solaris 11.1 allows attackers to cause a denial of service via unknown vectors.

    Published: 17 Apr 2014
    4.3
    Medium

    CVE-2014-2879

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote authenticated administrators to inject arbitrary web script or HTML via (1) the uploadPatch parameter to the System/Advanced page (settings_advanced.html) or (2) the uploadLicenses parameter in the License management (settings_upload_dlicense.html) page.

    Published: 17 Apr 2014
    5.8
    Medium

    CVE-2014-2880

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.

    Published: 17 Apr 2014
    4.3
    Medium

    CVE-2014-0984

    Last Modified: 12 Apr 2025

    The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route Permission Table entry password upon encountering the first incorrect character, which allows remote attackers to obtain passwords via a brute-force attack that relies on timing differences in responses to incorrect password guesses, aka a timing side-channel attack.

    Published: 17 Apr 2014
    1.9
    Low

    CVE-2011-3154

    Last Modified: 12 Apr 2025

    DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a symlink attack on the temporary file.

    Published: 17 Apr 2014
    7.8
    High

    CVE-2014-0644

    Last Modified: 12 Apr 2025

    EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, as demonstrated by reading the /etc/shadow file.

    Published: 17 Apr 2014
    4.7
    Medium

    CVE-2014-0645

    Last Modified: 12 Apr 2025

    EMC Cloud Tiering Appliance (CTA) 9.x through 10 SP1 and File Management Appliance (FMA) 7.x store DES password hashes for the root, super, and admin accounts, which makes it easier for context-dependent attackers to obtain sensitive information via a brute-force attack.

    Published: 17 Apr 2014
    7.5
    High

    CVE-2014-0182

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted config length in a savevm image.

    Published: 17 Apr 2014
    4.3
    Medium

    CVE-2014-4020

    Last Modified: 12 Apr 2025

    The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even though it was intended to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 17 Apr 2014
    7.5
    High

    CVE-2014-2913

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote attackers to execute arbitrary commands via a newline character in the -a option to libexec/check_nrpe. NOTE: this issue is disputed by multiple parties. It has been reported that the vendor allows newlines as "expected behavior." Also, this issue can only occur when the administrator enables the "dont_blame_nrpe" option in nrpe.conf despite the "HIGH security risk" warning within the comments

    Published: 17 Apr 2014
    3.5
    Low

    CVE-2014-4167

    Last Modified: 12 Apr 2025

    The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.

    Published: 17 Apr 2014
    7.5
    High

    CVE-2013-4694

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.

    Published: 16 Apr 2014
    7.5
    High

    CVE-2011-4192

    Last Modified: 12 Apr 2025

    kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."

    Published: 16 Apr 2014
    6.4
    Medium

    CVE-2014-2338

    Last Modified: 12 Apr 2025

    IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authentication, which triggers the IKE_SA state to be set to established.

    Published: 16 Apr 2014
    4
    Medium

    CVE-2014-1453

    Last Modified: 12 Apr 2025

    The NFS server (nfsserver) in FreeBSD 8.3 through 10.0 does not acquire locks in the proper order when converting a directory file handle to a vnode, which allows remote authenticated users to cause a denial of service (deadlock) via vectors involving a thread that uses the correct locking order.

    Published: 16 Apr 2014
    2.1
    Low

    CVE-2011-0993

    Last Modified: 12 Apr 2025

    SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 16 Apr 2014
    4.6
    Medium

    CVE-2011-4089

    Last Modified: 12 Apr 2025

    The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.

    Published: 16 Apr 2014
    3.6
    Low

    CVE-2011-4406

    Last Modified: 12 Apr 2025

    The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.

    Published: 16 Apr 2014
    7.5
    High

    CVE-2011-3180

    Last Modified: 12 Apr 2025

    kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2011-4193

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the overlay files tab in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted application, related to cloning.

    Published: 16 Apr 2014
    7.5
    High

    CVE-2011-4195

    Last Modified: 12 Apr 2025

    kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in an image name.

    Published: 16 Apr 2014
    4
    Medium

    CVE-2014-2424

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system.

    Published: 16 Apr 2014
    6.4
    Medium

    CVE-2014-2439

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 5.0 and 5.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Workspace Web Application.

    Published: 16 Apr 2014
    4.4
    Medium

    CVE-2014-2441

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.1.32, 4.2.24, and 4.3.10 allows local users to affect confidentiality, integrity, and availability via vectors related to Graphics driver (WDDM) for Windows guests.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2443

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect integrity via vectors related to PIA Core Technology.

    Published: 16 Apr 2014
    3.5
    Low

    CVE-2014-2445

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2014-2467.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2447

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect confidentiality via unknown vectors related to Integration Broker, a different vulnerability than CVE-2014-2437.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2448

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect confidentiality via unknown vectors related to Install and Packaging.

    Published: 16 Apr 2014
    6
    Medium

    CVE-2014-2455

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to User Interface.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2457

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile Product Lifecycle component in Oracle Supply Chain Products Suite 6.0 and 6.1.0 allows remote attackers to affect integrity via unknown vectors related to Install.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2458

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile Product Lifecycle component in Oracle Supply Chain Products Suite 6.1.0.3 and 6.1.1.3 allows remote attackers to affect integrity via unknown vectors related to Install.

    Published: 16 Apr 2014
    3.7
    Low

    CVE-2014-2459

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.3.2 and 6.3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Security.

    Published: 16 Apr 2014
    4
    Medium

    CVE-2014-2460

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, 6.2, 6.3, 6.3.1, 6.3.2, and 6.3.3 allows remote authenticated users to affect confidentiality via vectors related to CSV Management.

    Published: 16 Apr 2014