CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2014-2868

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-2869

    Last Modified: 12 Apr 2025

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as demonstrated by pathname, SQL server, e-mail address, and IP address information.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2013-4768

    Last Modified: 12 Apr 2025

    The web services APIs in Eucalyptus 2.0 through 3.4.1 allow remote attackers to cause a denial of service via vectors related to the "network connection clean up code" and (1) Cloud Controller (CLC), (2) Walrus, (3) Storage Controller (SC), and (4) VMware Broker (VB).

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2014-0413

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via vectors related to HTTP Request Handling, a different vulnerability than CVE-2014-0426.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-0414

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality via vectors related to HTTP Request Handling.

    Published: 15 Apr 2014
    4.6
    Medium

    CVE-2014-0421

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10, when running on the SPARC64-X Platform, allows local users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2014-0426

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via vectors related to HTTP Request Handling, a different vulnerability than CVE-2014-0413.

    Published: 15 Apr 2014
    4.6
    Medium

    CVE-2014-0442

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Solaris 9, 10, and 11.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Print Filter Utility.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-0450

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.7 and 11.1.1.8 allows remote attackers to affect confidentiality via unknown vectors related to People Connection.

    Published: 15 Apr 2014
    4.9
    Medium

    CVE-2014-0447

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2013-5876.

    Published: 15 Apr 2014
    9.3
    Critical

    CVE-2014-0514

    Last Modified: 12 Apr 2025

    The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-6636.

    Published: 15 Apr 2014
    4.9
    Medium

    CVE-2014-2384

    Last Modified: 12 Apr 2025

    vmx86.sys in VMware Workstation 10.0.1 build 1379776 and VMware Player 6.0.1 build 1379776 on Windows might allow local users to cause a denial of service (read access violation and system crash) via a crafted buffer in an IOCTL call. NOTE: the researcher reports "Vendor rated issue as non-exploitable."

    Published: 15 Apr 2014
    5.8
    Medium

    CVE-2014-1986

    Last Modified: 12 Apr 2025

    The Content Provider in the KOKUYO CamiApp application 1.21.1 and earlier for Android allows attackers to bypass intended access restrictions and read database information via a crafted application.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-2857

    Last Modified: 12 Apr 2025

    The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to files in the META-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this issue was SPLIT from CVE-2014-0053 due to different researchers per ADT5.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-2858

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 allows remote attackers to obtain sensitive information via unspecified vectors related to a "configured block." NOTE: this issue was SPLIT from CVE-2014-0053 per ADT2 due to different vulnerability types.

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2012-0214

    Last Modified: 12 Apr 2025

    The pkgAcqMetaClearSig::Failed method in apt-pkg/acquire-item.cc in Advanced Package Tool (APT) 0.8.11 through 0.8.15.10 and 0.8.16 before 0.8.16~exp13, when updating from repositories that use InRelease files, allows man-in-the-middle attackers to install arbitrary packages by preventing a user from downloading the new InRelease file, which leaves the original InRelease file active and makes it more difficult to detect that the Packages file is modified and unsigned.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-0053

    Last Modified: 12 Apr 2025

    The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files in the WEB-INF directory, which allows remote attackers to obtain sensitive information via a direct request. NOTE: this identifier has been SPLIT due to different researchers and different vulnerability types. See CVE-2014-2857 for the META-INF variant and CVE-2014-2858 for the directory traversal.

    Published: 15 Apr 2014
    6.9
    Medium

    CVE-2011-3628

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ubuntu 10.10, before 1.1.1-2ubuntu5.4 on Ubuntu 10.04 LTS, and before 0.99.7.1-5ubuntu6.5 on Ubuntu 8.04 LTS, when using certain configurations such as "session optional pam_motd.so", allows local users to gain privileges by modifying the PATH environment variable to reference a malicious command, as demonstrated via uname.

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2013-7368

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the gnew_template parameter to (1) users/profile.php, (2) articles/index.php, or (3) admin/polls.php; (4) category_id parameter to news/submit.php; news_id parameter to (5) news/send.php or (6) comments/add.php; or (7) post_subject or (8) thread_id parameter to posts/edit.php.

    Published: 15 Apr 2014
    2.1
    Low

    CVE-2014-2690

    Last Modified: 12 Apr 2025

    Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain administrator credentials by reading the log.

    Published: 15 Apr 2014
    7.8
    High

    CVE-2014-2842

    Last Modified: 12 Apr 2025

    Juniper ScreenOS 6.3 and earlier allows remote attackers to cause a denial of service (crash and restart or failover) via a malformed SSL/TLS packet.

    Published: 15 Apr 2014
    7.5
    High

    CVE-2014-0342

    Last Modified: 12 Apr 2025

    Multiple unrestricted file upload vulnerabilities in fileupload.php in PivotX before 2.3.9 allow remote authenticated users to execute arbitrary PHP code by uploading a file with a (1) .php or (2) .php# extension, and then accessing it via unspecified vectors.

    Published: 15 Apr 2014
    7.9
    High

    CVE-2014-0355

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows on the ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allow man-in-the-middle attackers to execute arbitrary code via (1) a long temp attribute in a yweather:condition element in a forecastrss file that is processed by the checkWeather function; the (2) WeatherCity or (3) WeatherDegree variable to the detectWeather function; unspecified input to the (4) UpnpAddRunRLQoS, (5) UpnpDeleteRunRLQoS, or (6) UpnpDeletePortCheckType function; or (7) the SET COUNTRY udps command.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-0357

    Last Modified: 12 Apr 2025

    Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modified contactID value, as demonstrated by a request from the iOS or Android application.

    Published: 15 Apr 2014
    7.8
    High

    CVE-2014-0358

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the file parameter in a getUpgradeStatus action to servlet/MGConfigData, (2) the download parameter in a download action to servlet/MGConfigData, (3) the download parameter in a port_svc action to servlet/MGConfigData, (4) the file parameter in a getfile action to servlet/Installer, or (5) the binfile parameter to servlet/MGConfigData.

    Published: 15 Apr 2014
    9
    Critical

    CVE-2014-0359

    Last Modified: 12 Apr 2025

    Xangati XSR before 11 and XNR before 7 allows remote attackers to execute arbitrary commands via shell metacharacters in a gui_input_test.pl params parameter to servlet/Installer.

    Published: 15 Apr 2014
    3.5
    Low

    CVE-2014-0341

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote authenticated users to inject arbitrary web script or HTML via the title field to (1) templates_internal/pages.tpl, (2) templates_internal/home.tpl, or (3) templates_internal/entries.tpl; (4) an event field to objects.php; or the (5) email or (6) nickname field to pages.php, related to templates_internal/users.tpl.

    Published: 15 Apr 2014
    6.1
    Medium

    CVE-2014-0353

    Last Modified: 12 Apr 2025

    The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to bypass authentication by using %2F sequences in place of / (slash) characters.

    Published: 15 Apr 2014
    7.8
    High

    CVE-2014-0354

    Last Modified: 12 Apr 2025

    The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 has a hardcoded password of qweasdzxc for an unspecified account, which allows remote attackers to obtain index.asp login access via an HTTP request.

    Published: 15 Apr 2014
    7.9
    High

    CVE-2014-0356

    Last Modified: 12 Apr 2025

    The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to execute arbitrary code via shell metacharacters in input to the (1) detectWeather, (2) set_language, (3) SystemCommand, or (4) NTPSyncWithHost function in management.c, or a (5) SET COUNTRY, (6) SET WLAN SSID, (7) SET WLAN CHANNEL, (8) SET WLAN STATUS, or (9) SET WLAN COUNTRY udps command.

    Published: 15 Apr 2014
    3.5
    Low

    CVE-2014-0348

    Last Modified: 12 Apr 2025

    The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9, Artiva Rm 3.1 MR7, Artiva Healthcare 5.2 MR5, and Artiva Architect 3.2 MR5, when the domain-name option is enabled, allows remote attackers to login to arbitrary domain accounts by using the corresponding username on a Windows client machine.

    Published: 15 Apr 2014
    4
    Medium

    CVE-2014-4233

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SRREP.

    Published: 15 Apr 2014
    10
    Critical

    CVE-2014-0429

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.

    Published: 15 Apr 2014
    7.5
    High

    CVE-2014-0446

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.

    Published: 15 Apr 2014
    7.5
    High

    CVE-2014-0452

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS, a different vulnerability than CVE-2014-0458 and CVE-2014-2423.

    Published: 15 Apr 2014
    7.5
    High

    CVE-2014-0458

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS, a different vulnerability than CVE-2014-0452 and CVE-2014-2423.

    Published: 15 Apr 2014
    4.3
    Medium

    CVE-2014-2413

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect integrity via unknown vectors related to Libraries.

    Published: 15 Apr 2014
    5.1
    Medium

    CVE-2014-2440

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the MySQL Client component in Oracle MySQL 5.5.36 and earlier and 5.6.16 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Apr 2014
    4
    Medium

    CVE-2014-2442

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated users to affect availability via vectors related to MyISAM.

    Published: 15 Apr 2014
    6.5
    Medium

    CVE-2014-2444

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to InnoDB.

    Published: 15 Apr 2014
    4
    Medium

    CVE-2014-2450

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

    Published: 15 Apr 2014
    4
    Medium

    CVE-2014-4207

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.

    Published: 15 Apr 2014
    4
    Medium

    CVE-2014-4238

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.6.17 and earlier allows remote authenticated users to affect availability via vectors related to SROPTZR.

    Published: 15 Apr 2014
    9.3
    Critical

    CVE-2014-2397

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-2401

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality via unknown vectors related to 2D.

    Published: 15 Apr 2014
    7.5
    High

    CVE-2014-2402

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2014-0432 and CVE-2014-0455.

    Published: 15 Apr 2014
    5
    Medium

    CVE-2014-2403

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via vectors related to JAXP.

    Published: 15 Apr 2014
    10
    Critical

    CVE-2014-2405

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-0462.

    Published: 15 Apr 2014
    6.4
    Medium

    CVE-2014-2409

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Deployment.

    Published: 15 Apr 2014
    9.3
    Critical

    CVE-2014-2410

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Java SE 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.

    Published: 15 Apr 2014