CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2012-1834

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the cms_tpv_admin_head function in functions.php in the CMS Tree Page View plugin before 0.8.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cms_tpv_view parameter to wp-admin/options-general.php.

    Published: 7 Apr 2014
    7.5
    High

    CVE-2014-0160

    Last Modified: 21 Apr 2026

    The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

    Published: 7 Apr 2014
    5
    Medium

    CVE-2014-3916

    Last Modified: 12 Apr 2025

    The str_buf_cat function in string.c in Ruby 1.9.3, 2.0.0, and 2.1 allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string.

    Published: 7 Apr 2014
    6.8
    Medium

    CVE-2013-5680

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code via a long USER command.

    Published: 6 Apr 2014
    4.3
    Medium

    CVE-2013-1946

    Last Modified: 12 Apr 2025

    The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows remote attackers to cause a denial of service via a GET request with an HTTP Accept header set to a non-HTML type, which can "interfere with Drupal's page cache."

    Published: 6 Apr 2014
    4.3
    Medium

    CVE-2012-5567

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.18, as used in Horde Groupware Webmail Edition before 4.0.9, allow remote attackers to inject arbitrary web script or HTML via crafted event location parameters in the (1) month, (2) monthlist, or (3) prevmonthlist fields, related to portal blocks.

    Published: 5 Apr 2014
    4.3
    Medium

    CVE-2012-6640

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Horde Internet Mail Program (IMP) before 5.0.22, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted SVG image attachment, a different vulnerability than CVE-2012-5565.

    Published: 5 Apr 2014
    4.3
    Medium

    CVE-2012-5566

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Kronolith Calendar Application H4 before 3.0.17, as used in Horde Groupware Webmail Edition before 4.0.8, allow remote attackers to inject arbitrary web script or HTML via the (1) tasks view or (2) search view.

    Published: 5 Apr 2014
    4.3
    Medium

    CVE-2012-5565

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in js/compose-dimp.js in Horde Internet Mail Program (IMP) before 5.0.24, as used in Horde Groupware Webmail Edition before 4.0.9, allows remote attackers to inject arbitrary web script or HTML via a crafted name for an attached file, related to the dynamic view.

    Published: 5 Apr 2014
    5
    Medium

    CVE-2014-2730

    Last Modified: 12 Apr 2025

    The XML parser in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013, and Office for Mac 2011, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption and persistent application hang) via a crafted XML document containing a large number of nested entity references, as demonstrated by a crafted text/plain e-mail message to Outlook, a similar issue to CVE-2003-1564.

    Published: 5 Apr 2014
    4
    Medium

    CVE-2014-2600

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors.

    Published: 5 Apr 2014
    4.3
    Medium

    CVE-2014-0337

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web interface on Huawei Echo Life HG8247 routers with software before V100R006C00SPC127 allows remote attackers to inject arbitrary web script or HTML via an invalid TELNET connection attempt with a crafted username that is not properly handled during construction of the "failed log-in attempts over telnet" log view.

    Published: 5 Apr 2014
    4.3
    Medium

    CVE-2014-0827

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM InfoSphere Optim Workload Replay 1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 5 Apr 2014
    6.1
    Medium

    CVE-2014-2144

    Last Modified: 12 Apr 2025

    Cisco IOS XR does not properly throttle ICMPv6 redirect packets, which allows remote attackers to cause a denial of service (IPv4 and IPv6 transit outage) via crafted redirect messages, aka Bug ID CSCum14266.

    Published: 5 Apr 2014
    4
    Medium

    CVE-2014-2145

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the messaging API in Cisco Unity Connection allows remote authenticated users to read arbitrary files via vectors related to unenforced access constraints for .wav files and the audio/x-wav MIME type, aka Bug ID CSCun91071.

    Published: 5 Apr 2014
    4.3
    Medium

    CVE-2014-0637

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the back-office case-management application in RSA Adaptive Authentication (On-Premise) 6.x and 7.x before 7.1 SP0 P2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Apr 2014
    4.3
    Medium

    CVE-2014-0638

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in RSA Adaptive Authentication (On-Premise) 6.x and 7.x before 7.1 SP0 P2 allows remote attackers to inject arbitrary web script or HTML via vectors involving FRAME elements, related to a "cross-frame scripting" issue.

    Published: 4 Apr 2014
    4.3
    Medium

    CVE-2014-2114

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in UserServlet in Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun24384.

    Published: 4 Apr 2014
    6.8
    Medium

    CVE-2014-2115

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun24250.

    Published: 4 Apr 2014
    4.3
    Medium

    CVE-2014-2116

    Last Modified: 12 Apr 2025

    Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject web pages and modify dynamic content via unspecified parameters, aka Bug ID CSCun37882.

    Published: 4 Apr 2014
    4.3
    Medium

    CVE-2014-2117

    Last Modified: 12 Apr 2025

    Multiple open redirect vulnerabilities in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters, aka Bug ID CSCun37909.

    Published: 4 Apr 2014
    7.5
    High

    CVE-2014-2210

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive information, bypass intended access restrictions, cause a denial of service, or possibly execute arbitrary code via unspecified vectors.

    Published: 4 Apr 2014
    5
    Medium

    CVE-2014-0789

    Last Modified: 25 Sept 2025

    Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a denial of service via long arguments to unspecified functions.

    Published: 4 Apr 2014
    5
    Medium

    CVE-2014-2143

    Last Modified: 12 Apr 2025

    The IKE implementation in Cisco IOS 15.4(1)T and earlier and IOS XE allows remote attackers to cause a denial of service (security-association drop) via crafted Main Mode packets, aka Bug ID CSCun31021.

    Published: 4 Apr 2014
    9.3
    Critical

    CVE-2013-3930

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Core FTP before 2.2 build 1785 allows remote FTP servers to execute arbitrary code via a crafted directory name in a CWD command reply.

    Published: 4 Apr 2014
    5
    Medium

    CVE-2012-4920

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the zing_forum_output function in forum.php in the Zingiri Forum (aka Forums) plugin before 1.4.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter to index.php.

    Published: 4 Apr 2014
    7.5
    High

    CVE-2012-5648

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in Foreman before 1.0.2 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) app/models/hostext/search.rb or (2) app/models/puppetclass.rb, related to the search mechanism.

    Published: 4 Apr 2014
    10
    Critical

    CVE-2012-6429

    Last Modified: 12 Apr 2025

    Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the password argument.

    Published: 4 Apr 2014
    4.3
    Medium

    CVE-2013-2287

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.

    Published: 4 Apr 2014
    7.5
    High

    CVE-2014-0592

    Last Modified: 12 Apr 2025

    Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instances, which allows remote attackers to bypass security group restrictions via unspecified vectors, related to floating IPs.

    Published: 4 Apr 2014
    4.9
    Medium

    CVE-2013-4544

    Last Modified: 12 Apr 2025

    hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these details are obtained from third party information.

    Published: 4 Apr 2014
    5.5
    Medium

    CVE-2014-0155

    Last Modified: 12 Apr 2025

    The ioapic_deliver function in virt/kvm/ioapic.c in the Linux kernel through 3.14.1 does not properly validate the kvm_irq_delivery_to_apic return value, which allows guest OS users to cause a denial of service (host OS crash) via a crafted entry in the redirection table of an I/O APIC. NOTE: the affected code was moved to the ioapic_service function before the vulnerability was announced.

    Published: 4 Apr 2014
    7.5
    High

    CVE-2014-1735

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 3.24.35.33, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 4 Apr 2014
    6.8
    Medium

    CVE-2014-2340

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that create website backups via a request to wp-admin/plugins.php.

    Published: 3 Apr 2014
    6.5
    Medium

    CVE-2013-6468

    Last Modified: 12 Apr 2025

    JBoss Drools, Red Hat JBoss BRMS before 6.0.1, and Red Hat JBoss BPM Suite before 6.0.1 allows remote authenticated users to execute arbitrary Java code via a (1) MVFLEX Expression Language (MVEL) or (2) Drools expression.

    Published: 3 Apr 2014
    7.5
    High

    CVE-2013-0735

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewtopic (1) remove_post, (2) sticky, or (3) closed action or (4) thread parameter in a postreply action to index.php.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2013-7352

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the show_statuses[] parameter, related to CVE-2013-2945.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2014-1298

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2014-1305

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

    Published: 2 Apr 2014
    9.3
    Critical

    CVE-2013-0729

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream in a PDF file.

    Published: 2 Apr 2014
    6.5
    Medium

    CVE-2013-2945

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

    Published: 2 Apr 2014
    4.3
    Medium

    CVE-2013-3484

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in dotCMS before 2.3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) _loginUserName parameter to application/login/login.html, (2) my_account_login parameter to c/portal_public/login, or (3) email parameter to forgotPassword.

    Published: 2 Apr 2014
    5
    Medium

    CVE-2014-1297

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate WebProcess IPC messages, which allows remote attackers to bypass a sandbox protection mechanism and read arbitrary files by leveraging WebProcess access.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2014-1304

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2014-1301

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2014-1302

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2014-1308

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2014-1309

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2014-1311

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

    Published: 2 Apr 2014
    6.8
    Medium

    CVE-2014-1310

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.

    Published: 2 Apr 2014