CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2014-2461

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 5.5.06, 6.0, 6.1, 6.2, 6.3, 6.3.1, 6.3.2, and 6.3.3 allows remote attackers to affect confidentiality via unknown vectors related to Security.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2463

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 4.63, 4.71, 5.0, and 5.1 allows remote attackers to affect integrity via unknown vectors related to Workspace Web Application, a different vulnerability than CVE-2014-4232.

    Published: 16 Apr 2014
    3.5
    Low

    CVE-2014-2464

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2465

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3 allows remote attackers to affect integrity via unknown vectors related to Security.

    Published: 16 Apr 2014
    2.1
    Low

    CVE-2014-2466

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 16 Apr 2014
    3.5
    Low

    CVE-2014-2467

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Security, a different vulnerability than CVE-2014-2445.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2468

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect integrity via vectors related to Open_UI, a different vulnerability than CVE-2014-4230.

    Published: 16 Apr 2014
    7.5
    High

    CVE-2014-2470

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Security.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2471

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 6.0 and 6.1 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.

    Published: 16 Apr 2014
    4
    Medium

    CVE-2014-2452

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5 allows remote authenticated users to affect availability via unknown vectors related to Webserver Plugin.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2453

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect integrity via unknown vectors related to User Interface.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2454

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Hyperion Common Admin component in Oracle Hyperion 11.1.2.2 and 11.1.2.3 allows remote attackers to affect confidentiality via unknown vectors related to User Interface.

    Published: 16 Apr 2014
    6.5
    Medium

    CVE-2014-2411

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Identity Analytics component in Oracle Fusion Middleware Oracle Identity Analytics 11.1.1.5 and Sun Role Manager 5.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Security.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2415

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality, a different vulnerability than CVE-2014-2407, CVE-2014-2416, CVE-2014-2417, and CVE-2014-2418.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2416

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality, a different vulnerability than CVE-2014-2407, CVE-2014-2415, CVE-2014-2417, and CVE-2014-2418.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2417

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality, a different vulnerability than CVE-2014-2407, CVE-2014-2415, CVE-2014-2416, and CVE-2014-2418.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2418

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality, a different vulnerability than CVE-2014-2407, CVE-2014-2415, CVE-2014-2416, and CVE-2014-2417.

    Published: 16 Apr 2014
    4
    Medium

    CVE-2014-2425

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 16 Apr 2014
    4.9
    Medium

    CVE-2014-2426

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity and availability via unknown vectors related to Admin Console.

    Published: 16 Apr 2014
    4
    Medium

    CVE-2014-2429

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise CS Campus Self Service component in Oracle PeopleSoft Products 9.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Campus Mobile.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2433

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote attackers to affect availability via unknown vectors related to Integration Broker.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2437

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect confidentiality via unknown vectors related to Integration Broker, a different vulnerability than CVE-2014-2447.

    Published: 16 Apr 2014
    4
    Medium

    CVE-2014-2446

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via vectors related to QAS.

    Published: 16 Apr 2014
    4
    Medium

    CVE-2014-2449

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS Talent Acquisition Manager component in Oracle PeopleSoft Products 9.0, 9.1, and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 16 Apr 2014
    3.5
    Low

    CVE-2014-0465

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update 2 Patch 5 allows remote authenticated users to affect integrity via unknown vectors related to Admin Console.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2399

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.

    Published: 16 Apr 2014
    4.3
    Medium

    CVE-2014-2400

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2399.

    Published: 16 Apr 2014
    4
    Medium

    CVE-2014-2404

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10.1.4.3, 11.1.1.3.0, 11.1.1.5.0, 11.1.1.7.0, 11.1.2.0.0, 11.1.2.1.0, and 11.1.2.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to WebGate.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2407

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Data Quality, a different vulnerability than CVE-2014-2415, CVE-2014-2416, CVE-2014-2417, and CVE-2014-2418.

    Published: 16 Apr 2014
    6.6
    Medium

    CVE-2014-2408

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to the "Grant Any Object Privilege."

    Published: 16 Apr 2014
    8.5
    High

    CVE-2014-2406

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to "Advisor" and "Select Any Dictionary" privileges.

    Published: 16 Apr 2014
    5
    Medium

    CVE-2014-2872

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory listing via unspecified vectors.

    Published: 15 Apr 2014
    7.5
    High

    CVE-2014-2859

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2014-2860

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inject arbitrary web script or HTML via a crafted HTTP request to a (1) ColdFusion or (2) JavaScript component.

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2014-2861

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes only the "alert" string.

    Published: 15 Apr 2014
    6.5
    Medium

    CVE-2014-2862

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perform actions via unknown vectors.

    Published: 15 Apr 2014
    10
    Critical

    CVE-2014-2863

    Last Modified: 12 Apr 2025

    Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname in a parameter.

    Published: 15 Apr 2014
    10
    Critical

    CVE-2014-2864

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter containing directory traversal sequences.

    Published: 15 Apr 2014
    7.5
    High

    CVE-2014-2865

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demonstrated by using this character within a pathname on the drive containing the web root directory of a ColdFusion installation.

    Published: 15 Apr 2014
    10
    Critical

    CVE-2014-2866

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to perform unspecified operations by modifying this code.

    Published: 15 Apr 2014
    10
    Critical

    CVE-2014-2867

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code by uploading a ColdFusion page, and then accessing it via unspecified vectors.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-2870

    Last Modified: 12 Apr 2025

    The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database, which makes it easier for context-dependent attackers to obtain sensitive information via unspecified vectors.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-2871

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-2873

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackers to obtain sensitive server information by using a predictable name in a request for a file.

    Published: 15 Apr 2014
    10
    Critical

    CVE-2014-2874

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unspecified context.

    Published: 15 Apr 2014
    5.5
    Medium

    CVE-2014-0642

    Last Modified: 12 Apr 2025

    EMC Documentum Content Server before 6.7 SP1 P26, 6.7 SP2 before P13, 7.0 before P13, and 7.1 before P02 allows remote authenticated users to bypass intended access restrictions and read metadata from certain folders via unspecified vectors.

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2014-0922

    Last Modified: 12 Apr 2025

    IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (resource consumption) via WebSockets MQ Telemetry Transport (MQTT) data.

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2014-0923

    Last Modified: 12 Apr 2025

    IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon restart) via crafted MQ Telemetry Transport (MQTT) authentication data.

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2014-0921

    Last Modified: 12 Apr 2025

    The server in IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 allows remote attackers to cause a denial of service (daemon crash and message data loss) via malformed headers during a WebSockets connection upgrade.

    Published: 15 Apr 2014
    4.6
    Medium

    CVE-2014-0924

    Last Modified: 12 Apr 2025

    IBM MessageSight 1.x before 1.1.0.0-IBM-IMA-IT01015 does not verify that all of the characters of a password are correct, which makes it easier for remote authenticated users to bypass intended access restrictions by leveraging knowledge of a password substring.

    Published: 15 Apr 2014