CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2014-0981

    Last Modified: 12 Apr 2025

    VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.

    Published: 28 Mar 2014
    10
    Critical

    CVE-2014-1982

    Last Modified: 12 Apr 2025

    The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmware 3.5 allows remote attackers to gain privileges and execute arbitrary commands via a direct request to cli.html.

    Published: 28 Mar 2014
    5
    Medium

    CVE-2014-2590

    Last Modified: 12 Apr 2025

    The web management interface in Siemens RuggedCom ROS before 3.11, ROS 3.11 before 3.11.5 for RS950G, ROS 3.12, and ROS 4.0 for RSG2488 allows remote attackers to cause a denial of service (interface outage) via crafted HTTP packets.

    Published: 28 Mar 2014
    7.7
    High

    CVE-2014-0633

    Last Modified: 12 Apr 2025

    The GUI in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not properly validate session-timeout values, which might make it easier for remote attackers to execute arbitrary code by leveraging an unattended workstation.

    Published: 28 Mar 2014
    6
    Medium

    CVE-2014-0634

    Last Modified: 12 Apr 2025

    EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 28 Mar 2014
    7.5
    High

    CVE-2014-0635

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 28 Mar 2014
    9.3
    Critical

    CVE-2013-0662

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.

    Published: 28 Mar 2014
    9
    Critical

    CVE-2014-0632

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 28 Mar 2014
    5
    Medium

    CVE-2014-2668

    Last Modified: 12 Apr 2025

    Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

    Published: 28 Mar 2014
    4.3
    Medium

    CVE-2013-0734

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) search_words parameter in a search action to wpf.class.php or (2) togroupusers parameter in an add_user_togroup action to fs-admin/fs-admin.php.

    Published: 28 Mar 2014
    4.3
    Medium

    CVE-2013-0807

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS 3.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the section parameter in a new_section action to index.php.

    Published: 28 Mar 2014
    4.3
    Medium

    CVE-2013-2695

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in invite.php in the WP Symposium plugin before 13.04 for WordPress allows remote attackers to inject arbitrary web script or HTML via the u parameter.

    Published: 28 Mar 2014
    5.8
    Medium

    CVE-2013-2694

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in invite.php in the WP Symposium plugin 13.04 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the u parameter.

    Published: 28 Mar 2014
    3.3
    Low

    CVE-2014-2667

    Last Modified: 12 Apr 2025

    Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.

    Published: 28 Mar 2014
    2.1
    Low

    CVE-2014-0056

    Last Modified: 12 Apr 2025

    The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.

    Published: 28 Mar 2014
    6.8
    Medium

    CVE-2014-0466

    Last Modified: 12 Apr 2025

    The fixps script in a2ps 4.14 does not use the -dSAFER option when executing gs, which allows context-dependent attackers to delete arbitrary files or execute arbitrary commands via a crafted PostScript file.

    Published: 28 Mar 2014
    7.1
    High

    CVE-2014-2111

    Last Modified: 12 Apr 2025

    The Application Layer Gateway (ALG) module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted DNS packets, aka Bug ID CSCue00996.

    Published: 27 Mar 2014
    7.8
    High

    CVE-2014-2112

    Last Modified: 12 Apr 2025

    The SSL VPN (aka WebVPN) feature in Cisco IOS 15.1 through 15.4 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP requests, aka Bug ID CSCuf51357.

    Published: 27 Mar 2014
    7.8
    High

    CVE-2014-2106

    Last Modified: 12 Apr 2025

    Cisco IOS 15.3M before 15.3(3)M2 and IOS XE 3.10.xS before 3.10.2S allow remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCug45898.

    Published: 27 Mar 2014
    7.1
    High

    CVE-2014-2107

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2 and 15.0 through 15.3, when used with the Kailash FPGA before 2.6 on RSP720-3C-10GE and RSP720-3CXL-10GE devices, allows remote attackers to cause a denial of service (route switch processor outage) via crafted IP packets, aka Bug ID CSCug84789.

    Published: 27 Mar 2014
    7.8
    High

    CVE-2014-2108

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.2 through 3.7 before 3.7.5S and 3.8 through 3.10 before 3.10.1S allow remote attackers to cause a denial of service (device reload) via a malformed IKEv2 packet, aka Bug ID CSCui88426.

    Published: 27 Mar 2014
    7.8
    High

    CVE-2014-2109

    Last Modified: 12 Apr 2025

    The TCP Input module in Cisco IOS 12.2 through 12.4 and 15.0 through 15.4, when NAT is used, allows remote attackers to cause a denial of service (memory consumption or device reload) via crafted TCP packets, aka Bug IDs CSCuh33843 and CSCuj41494.

    Published: 27 Mar 2014
    4.3
    Medium

    CVE-2014-2118

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in dashboard-related HTML documents in Cisco Prime Security Manager (aka PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun50687.

    Published: 27 Mar 2014
    7.8
    High

    CVE-2014-2113

    Last Modified: 12 Apr 2025

    Cisco IOS 15.1 through 15.3 and IOS XE 3.3 and 3.5 before 3.5.2E; 3.7 before 3.7.5S; and 3.8, 3.9, and 3.10 before 3.10.2S allow remote attackers to cause a denial of service (I/O memory consumption and device reload) via a malformed IPv6 packet, aka Bug ID CSCui59540.

    Published: 27 Mar 2014
    Unknown

    CVE-2014-5880

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5880. Reason: This candidate is a duplicate of CVE-2013-5880. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2013-5880 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Mar 2014
    Unknown

    CVE-2014-5795

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5795. Reason: This candidate is a duplicate of CVE-2013-5795. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2013-5795 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Mar 2014
    4.3
    Medium

    CVE-2014-2326

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Mar 2014
    9.3
    Critical

    CVE-2013-0732

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in PDFCore8.dll in Nuance PDF Reader before 8.1 allows remote attackers to execute arbitrary code via crafted font table directory values in a TTF file, related to naming table entries.

    Published: 27 Mar 2014
    6.5
    Medium

    CVE-2013-2559

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

    Published: 27 Mar 2014
    9.3
    Critical

    CVE-2013-3481

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Artweaver Plus and Free before 3.1.5 allows remote attackers to execute arbitrary code via a crafted JPG image file.

    Published: 27 Mar 2014
    6.8
    Medium

    CVE-2013-7346

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the sort parameter to system/authors/, related to CVE-2013-2559.

    Published: 27 Mar 2014
    4.3
    Medium

    CVE-2014-0623

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Self-Service Console in EMC RSA Authentication Manager 7.1 before SP4 P32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross frame scripting" issue.

    Published: 27 Mar 2014
    10
    Critical

    CVE-2014-0511

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Adobe Reader 11.0.06 allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.

    Published: 27 Mar 2014
    10
    Critical

    CVE-2014-0512

    Last Modified: 12 Apr 2025

    Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.

    Published: 27 Mar 2014
    10
    Critical

    CVE-2014-0506

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR before 13.0.0.83 on Android, Adobe AIR SDK before 13.0.0.83, and Adobe AIR SDK & Compiler before 13.0.0.83 allows remote attackers to execute arbitrary code, and possibly bypass an Internet Explorer sandbox protection mechanism, via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.

    Published: 27 Mar 2014
    5.5
    Medium

    CVE-2014-0077

    Last Modified: 12 Apr 2025

    drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host OS crash) or possibly gain privileges on the host OS via crafted packets, related to the handle_rx and get_rx_bufs functions.

    Published: 27 Mar 2014
    6
    Medium

    CVE-2014-0105

    Last Modified: 12 Apr 2025

    The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve user tokens from memcache, which allows remote authenticated users to gain privileges in opportunistic circumstances via a large number of requests, related to an "interaction between eventlet and python-memcached."

    Published: 27 Mar 2014
    9.8
    Critical

    CVE-2014-0156

    Last Modified: 21 Nov 2024

    Awesome spawn contains OS command injection vulnerability, which allows execution of additional commands passed to Awesome spawn as arguments. If untrusted input was included in command arguments, attacker could use this flaw to execute arbitrary command.

    Published: 27 Mar 2014
    6.8
    Medium

    CVE-2014-2525

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the yaml_parser_scan_uri_escapes function in LibYAML before 0.1.6 allows context-dependent attackers to execute arbitrary code via a long sequence of percent-encoded characters in a URI in a YAML file.

    Published: 27 Mar 2014
    10
    Critical

    CVE-2014-1300

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute arbitrary code with root privileges via unknown vectors, as demonstrated by Google during a Pwn4Fun competition at CanSecWest 2014.

    Published: 26 Mar 2014
    10
    Critical

    CVE-2014-1303

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Liang Chen during a Pwn2Own competition at CanSecWest 2014.

    Published: 26 Mar 2014
    2.1
    Low

    CVE-2013-3976

    Last Modified: 12 Apr 2025

    The (1) Data Protection for Exchange component 6.1 before 6.1.3.4 and 6.3 before 6.3.1 in IBM Tivoli Storage Manager for Mail and the (2) FlashCopy Manager for Exchange component 2.2 and 3.1 before 3.1.1 in IBM Tivoli Storage FlashCopy Manager do not properly constrain mailbox contents during certain PST restore operations, which allows remote authenticated users to read the personal e-mail of other users in opportunistic circumstances by launching an e-mail client after an administrator performs a multiple-mailbox restore.

    Published: 26 Mar 2014
    4.9
    Medium

    CVE-2013-3997

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 26 Mar 2014
    3.5
    Low

    CVE-2013-3998

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 26 Mar 2014
    3.5
    Low

    CVE-2014-0848

    Last Modified: 12 Apr 2025

    The (1) ssl.conf and (2) httpd.conf files in the Apache HTTP Server component in IBM Netezza Performance Portal 2.0 before 2.0.0.4 have weak SSLCipherSuite values, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.

    Published: 26 Mar 2014
    7.6
    High

    CVE-2014-0904

    Last Modified: 12 Apr 2025

    The update process in IBM Security AppScan Standard 7.9 through 8.8 does not require integrity checks of downloaded files, which allows remote attackers to execute arbitrary code via a crafted file.

    Published: 26 Mar 2014
    4.3
    Medium

    CVE-2014-1827

    Last Modified: 12 Apr 2025

    The iThoughtsHD app 4.19 for iOS on iPad devices, when the WiFi Transfer feature is used, allows remote attackers to upload arbitrary files by placing a %00 sequence after a dangerous extension, as demonstrated by a .html%00.txt file.

    Published: 26 Mar 2014
    4.3
    Medium

    CVE-2014-1828

    Last Modified: 12 Apr 2025

    The iThoughts web server in the iThoughtsHD app 4.19 for iOS on iPad devices allows remote attackers to cause a denial of service (disk consumption) by uploading a large file.

    Published: 26 Mar 2014
    2.6
    Low

    CVE-2014-1826

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the iThoughtsHD app 4.19 for iOS on iPad devices, when the WiFi Transfer feature is used, allows remote attackers to inject arbitrary web script or HTML via a crafted map name.

    Published: 26 Mar 2014
    6.2
    Medium

    CVE-2014-0147

    Last Modified: 21 Nov 2024

    Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount() routine.

    Published: 26 Mar 2014