CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2014-0189

    Last Modified: 12 Apr 2025

    virt-who uses world-readable permissions for /etc/sysconfig/virt-who, which allows local users to obtain password for hypervisors by reading the file.

    Published: 26 Mar 2014
    6.4
    Medium

    CVE-2014-0138

    Last Modified: 12 Apr 2025

    The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.

    Published: 26 Mar 2014
    5.8
    Medium

    CVE-2014-0139

    Last Modified: 12 Apr 2025

    cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

    Published: 26 Mar 2014
    8.6
    High

    CVE-2014-0144

    Last Modified: 21 Nov 2024

    QEMU before 2.0.0 block drivers for CLOOP, QCOW2 version 2 and various other image formats are vulnerable to potential memory corruptions, integer/buffer overflows or crash caused by missing input validations which could allow a remote user to execute arbitrary code on the host with the privileges of the QEMU process.

    Published: 26 Mar 2014
    7.8
    High

    CVE-2014-0145

    Last Modified: 20 Apr 2025

    Multiple buffer overflows in QEMU before 1.7.2 and 2.x before 2.0.0, allow local users to cause a denial of service (crash) or possibly execute arbitrary code via a large (1) L1 table in the qcow2_snapshot_load_tmp in the QCOW 2 block driver (block/qcow2-snapshot.c) or (2) uncompressed chunk, (3) chunk length, or (4) number of sectors in the DMG block driver (block/dmg.c).

    Published: 26 Mar 2014
    5.5
    Medium

    CVE-2014-0142

    Last Modified: 20 Apr 2025

    QEMU, possibly before 2.0.0, allows local users to cause a denial of service (divide-by-zero error and crash) via a zero value in the (1) tracks field to the seek_to_sector function in block/parallels.c or (2) extent_size field in the bochs function in block/bochs.c.

    Published: 26 Mar 2014
    7
    High

    CVE-2014-0143

    Last Modified: 20 Apr 2025

    Multiple integer overflows in the block drivers in QEMU, possibly before 2.0.0, allow local users to cause a denial of service (crash) via a crafted catalog size in (1) the parallels_open function in block/parallels.c or (2) bochs_open function in bochs.c, a large L1 table in the (3) qcow2_snapshot_load_tmp in qcow2-snapshot.c or (4) qcow2_grow_l1_table function in qcow2-cluster.c, (5) a large request in the bdrv_check_byte_request function in block.c and other block drivers, (6) crafted cluster indexes in the get_refcount function in qcow2-refcount.c, or (7) a large number of blocks in the cloop_open function in cloop.c, which trigger buffer overflows, memory corruption, large memory allocations and out-of-bounds read and writes.

    Published: 26 Mar 2014
    5.5
    Medium

    CVE-2014-0146

    Last Modified: 20 Apr 2025

    The qcow2_open function in the (block/qcow2.c) in QEMU before 1.7.2 and 2.x before 2.0.0 allows local users to cause a denial of service (NULL pointer dereference) via a crafted image which causes an error, related to the initialization of the snapshot_offset and nb_snapshots fields.

    Published: 26 Mar 2014
    5.5
    Medium

    CVE-2014-0148

    Last Modified: 21 Nov 2024

    Qemu before 2.0 block driver for Hyper-V VHDX Images is vulnerable to infinite loops and other potential issues when calculating BAT entries, due to missing bounds checks for block_size and logical_sector_size variables. These are used to derive other fields like 'sectors_per_block' etc. A user able to alter the Qemu disk image could ise this flaw to crash the Qemu instance resulting in DoS.

    Published: 26 Mar 2014
    4.6
    Medium

    CVE-2014-2739

    Last Modified: 12 Apr 2025

    The cma_req_handler function in drivers/infiniband/core/cma.c in the Linux kernel 3.14.x through 3.14.1 attempts to resolve an RDMA over Converged Ethernet (aka RoCE) address that is properly resolved within a different module, which allows remote attackers to cause a denial of service (incorrect pointer dereference and system crash) via crafted network traffic.

    Published: 26 Mar 2014
    5
    Medium

    CVE-2013-5444

    Last Modified: 12 Apr 2025

    The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encrypted credentials via unspecified vectors.

    Published: 25 Mar 2014
    5
    Medium

    CVE-2013-5445

    Last Modified: 12 Apr 2025

    IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext information by leveraging knowledge of a static decryption key.

    Published: 25 Mar 2014
    4.9
    Medium

    CVE-2014-0343

    Last Modified: 12 Apr 2025

    The web interface on Virtual Access GW6110A routers with software 9.00 before 9.09.27, 9.50 before 9.50.21, and 10.00 before 10.00.21 allows remote authenticated users to gain privileges via a modified JavaScript variable.

    Published: 25 Mar 2014
    3.5
    Low

    CVE-2014-0884

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Mar 2014
    6.8
    Medium

    CVE-2014-0885

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

    Published: 25 Mar 2014
    7.1
    High

    CVE-2014-0886

    Last Modified: 12 Apr 2025

    The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors.

    Published: 25 Mar 2014
    7.1
    High

    CVE-2014-0887

    Last Modified: 12 Apr 2025

    The Admin Web UI in IBM Lotus Protector for Mail Security 2.8.x before 2.8.1-22905 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.

    Published: 25 Mar 2014
    6.8
    Medium

    CVE-2013-5443

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 25 Mar 2014
    2.6
    Low

    CVE-2013-5951

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in eXtplorer 2.1.3, when used as a component for Joomla!, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) application.js.php in scripts/ or (2) admin.php, (3) copy_move.php, (4) functions.php, (5) header.php, or (6) upload.php in include/.

    Published: 25 Mar 2014
    5
    Medium

    CVE-2014-2386

    Last Modified: 12 Apr 2025

    Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vectors to the (1) display_nav_table, (2) print_export_link, (3) page_num_selector, or (4) page_limit_selector function in cgi/cgiutils.c or (5) status_page_num_selector function in cgi/status.c, which triggers a stack-based buffer overflow.

    Published: 25 Mar 2014
    6.1
    Medium

    CVE-2014-2526

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7 allow remote attackers to inject arbitrary web script or HTML via the (1) sForumName or (2) sDescription parameter to Forum/manage/ForumManager.lsp; (3) sHint, (4) sWord, or (5) nId parameter to Forum/manage/hangman.lsp; (6) user parameter to rtl/protected/admin/wizard/setuser.lsp; (7) name or (8) email parameter to feedback.lsp; (9) lname or (10) url parameter to private/manage/PageManager.lsp; (11) cmd parameter to fs; (12) newname, (13) description, (14) firstname, (15) lastname, or (16) id parameter to rtl/protected/mail/manage/list.lsp; or (17) PATH_INFO to fs/.

    Published: 25 Mar 2014
    5
    Medium

    CVE-2013-1604

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.

    Published: 25 Mar 2014
    7.5
    High

    CVE-2013-1605

    Last Modified: 12 Apr 2025

    Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in a GET request.

    Published: 25 Mar 2014
    4.3
    Medium

    CVE-2014-2016

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in OXID eShop Professional and Community Edition 4.6.8 and earlier, 4.7.x before 4.7.11, and 4.8.x before 4.8.4, and Enterprise Edition 4.6.8 and earlier, 5.0.x before 5.0.11 and 5.1.x before 5.1.4 allow remote attackers to inject arbitrary web script or HTML via the searchtag parameter to the getTag function in (1) application/controllers/details.php or (2) application/controllers/tag.php.

    Published: 25 Mar 2014
    1.9
    Low

    CVE-2014-1515

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the SD card, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application.

    Published: 25 Mar 2014
    5
    Medium

    CVE-2014-0628

    Last Modified: 12 Apr 2025

    The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

    Published: 25 Mar 2014
    5.5
    Medium

    CVE-2014-0055

    Last Modified: 12 Apr 2025

    The get_rx_bufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel package before 2.6.32-431.11.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle vhost_get_vq_desc errors, which allows guest OS users to cause a denial of service (host OS crash) via unspecified vectors.

    Published: 25 Mar 2014
    3.5
    Low

    CVE-2014-0134

    Last Modified: 12 Apr 2025

    The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain compute host files by overwriting an instance disk with a crafted image.

    Published: 25 Mar 2014
    4.9
    Medium

    CVE-2014-2599

    Last Modified: 12 Apr 2025

    The HVMOP_set_mem_access HVM control operations in Xen 4.1.x for 32-bit and 4.1.x through 4.4.x for 64-bit allow local guest administrators to cause a denial of service (CPU consumption) by leveraging access to certain service domains for HVM guests and a large input.

    Published: 25 Mar 2014
    5
    Medium

    CVE-2014-7204

    Last Modified: 12 Apr 2025

    jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.

    Published: 25 Mar 2014
    7.8
    High

    CVE-2014-1761

    Last Modified: 21 Apr 2026

    Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, as exploited in the wild in March 2014.

    Published: 24 Mar 2014
    4.3
    Medium

    CVE-2012-6430

    Last Modified: 16 Mar 2026

    Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded before December 19, 2012, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to admin.php. NOTE: this might be a duplicate of CVE-2008-4140.

    Published: 24 Mar 2014
    6.5
    Medium

    CVE-2013-1408

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2) orderby parameter to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

    Published: 24 Mar 2014
    10
    Critical

    CVE-2012-4886

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code via a long BSTR string.

    Published: 24 Mar 2014
    6.5
    Medium

    CVE-2014-2653

    Last Modified: 28 May 2026

    The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.

    Published: 24 Mar 2014
    6.8
    Medium

    CVE-2014-0090

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.

    Published: 24 Mar 2014
    5.8
    Medium

    CVE-2014-2583

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in pam_timestamp.c in the pam_timestamp module for Linux-PAM (aka pam) 1.1.8 allow local users to create arbitrary files or possibly bypass authentication via a .. (dot dot) in the (1) PAM_RUSER value to the get_ruser function or (2) PAM_TTY value to the check_tty function, which is used by the format_timestamp_name function.

    Published: 24 Mar 2014
    6.5
    Medium

    CVE-2013-2143

    Last Modified: 12 Apr 2025

    The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

    Published: 24 Mar 2014
    4.3
    Medium

    CVE-2014-0089

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in app/views/common/500.html.erb in Foreman 1.4.x before 1.4.2 allows remote authenticated users to inject arbitrary web script or HTML via the bookmark name when adding a bookmark.

    Published: 24 Mar 2014
    7.5
    High

    CVE-2014-0107

    Last Modified: 12 Apr 2025

    The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is enabled, which allows remote attackers to bypass expected restrictions and load arbitrary classes or access external resources via a crafted (1) xalan:content-header, (2) xalan:entities, (3) xslt:content-header, or (4) xslt:entities property, or a Java property that is bound to the XSLT 1.0 system-property function.

    Published: 24 Mar 2014
    4.4
    Medium

    CVE-2014-2580

    Last Modified: 12 Apr 2025

    The netback driver in Xen, when using certain Linux versions that do not allow sleeping in softirq context, allows local guest administrators to cause a denial of service ("scheduling while atomic" error and host crash) via a malformed packet, which causes a mutex to be taken when trying to disable the interface.

    Published: 24 Mar 2014
    6.9
    Medium

    CVE-2014-5033

    Last Modified: 12 Apr 2025

    KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, related to CVE-2013-4288 and "PID reuse race conditions."

    Published: 24 Mar 2014
    5
    Medium

    CVE-2015-6496

    Last Modified: 12 Apr 2025

    conntrackd in conntrack-tools 1.4.2 and earlier does not ensure that the optional kernel modules are loaded before using them, which allows remote attackers to cause a denial of service (crash) via a (1) DCCP, (2) SCTP, or (3) ICMPv6 packet.

    Published: 24 Mar 2014
    6.5
    Medium

    CVE-2016-2533

    Last Modified: 12 Apr 2025

    Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.

    Published: 24 Mar 2014
    4.3
    Medium

    CVE-2014-2586

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote attackers to inject arbitrary web script or HTML via a crafted password.

    Published: 23 Mar 2014
    6.5
    Medium

    CVE-2014-2587

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter).

    Published: 23 Mar 2014
    4
    Medium

    CVE-2014-2588

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter.

    Published: 23 Mar 2014
    4.3
    Medium

    CVE-2014-2589

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Dashboard Backend service (stats/dashboard.jsp) in SonicWall Network Security Appliance (NSA) 2400 allows remote attackers to inject arbitrary web script or HTML via the sn parameter.

    Published: 23 Mar 2014
    4.9
    Medium

    CVE-2014-2585

    Last Modified: 12 Apr 2025

    ownCloud before 5.0.15 and 6.x before 6.0.2, when the file_external app is enabled, allows remote authenticated users to mount the local filesystem in the user's ownCloud via the mount configuration.

    Published: 23 Mar 2014
    6.5
    Medium

    CVE-2013-7344

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in core/settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via unknown vectors. NOTE: this issue was SPLIT from CVE-2013-0303 due to different affected versions.

    Published: 23 Mar 2014