CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2014-2057

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 6.0.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Mar 2014
    6.5
    Medium

    CVE-2013-0303

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in core/ajax/translations.php in ownCloud before 4.0.12 and 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via unknown vectors. NOTE: this entry has been SPLIT due to different affected versions. The core/settings.php issue is covered by CVE-2013-7344.

    Published: 23 Mar 2014
    5
    Medium

    CVE-2014-6421

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the SDP dissector in Wireshark 1.10.x before 1.10.10 allows remote attackers to cause a denial of service (application crash) via a crafted packet that leverages split memory ownership between the SDP and RTP dissectors.

    Published: 23 Mar 2014
    5
    Medium

    CVE-2014-6422

    Last Modified: 12 Apr 2025

    The SDP dissector in Wireshark 1.10.x before 1.10.10 creates duplicate hashtables for a media channel, which allows remote attackers to cause a denial of service (application crash) via a crafted packet to the RTP dissector.

    Published: 23 Mar 2014
    4
    Medium

    CVE-2014-2572

    Last Modified: 12 Apr 2025

    mod/assign/externallib.php in Moodle 2.6.x before 2.6.2 does not properly handle assignment web-service parameters, which might allow remote authenticated users to modify grade metadata via unspecified vectors.

    Published: 22 Mar 2014
    6.1
    Medium

    CVE-2014-2252

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted PROFINET packets, a different vulnerability than CVE-2014-2253.

    Published: 22 Mar 2014
    7.8
    High

    CVE-2014-2254

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTP packets, a different vulnerability than CVE-2014-2255.

    Published: 22 Mar 2014
    7.8
    High

    CVE-2014-2256

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted ISO-TSAP packets, a different vulnerability than CVE-2014-2257.

    Published: 22 Mar 2014
    7.8
    High

    CVE-2014-2258

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTPS packets, a different vulnerability than CVE-2014-2259.

    Published: 22 Mar 2014
    4.3
    Medium

    CVE-2013-7343

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in flowplayer.swf in the Flash fallback feature in Flowplayer HTML5 5.4.3 allows remote attackers to inject arbitrary web script or HTML by using URL encoding within the callback parameter name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7342.

    Published: 22 Mar 2014
    4.9
    Medium

    CVE-2014-0122

    Last Modified: 12 Apr 2025

    mod/chat/chat_ajax.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly check for the mod/chat:chat capability during chat sessions, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by remaining in a chat session after an intra-session capability removal by an administrator.

    Published: 22 Mar 2014
    4
    Medium

    CVE-2014-0124

    Last Modified: 12 Apr 2025

    The identity-reporting implementations in mod/forum/renderer.php and mod/quiz/override_form.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 do not properly restrict the display of e-mail addresses, which allows remote authenticated users to obtain sensitive information by using the (1) Forum or (2) Quiz module.

    Published: 22 Mar 2014
    5.8
    Medium

    CVE-2014-0125

    Last Modified: 12 Apr 2025

    repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, which allows remote attackers to bypass intended Alfresco Repository file restrictions by impersonating a file's owner.

    Published: 22 Mar 2014
    6.8
    Medium

    CVE-2014-0126

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.

    Published: 22 Mar 2014
    4
    Medium

    CVE-2014-0129

    Last Modified: 12 Apr 2025

    badges/mybadges.php in Moodle 2.5.x before 2.5.5 and 2.6.x before 2.6.2 does not properly track the user to whom a badge was issued, which allows remote authenticated users to modify the visibility of an arbitrary badge via unspecified vectors.

    Published: 22 Mar 2014
    3.5
    Low

    CVE-2014-2571

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the quiz_question_tostring function in mod/quiz/editlib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a quiz question.

    Published: 22 Mar 2014
    4.3
    Medium

    CVE-2013-7341

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.

    Published: 22 Mar 2014
    4.3
    Medium

    CVE-2013-7342

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in flowplayer.swf in the Flash fallback feature in Flowplayer HTML5 5.4.1 allows remote attackers to inject arbitrary web script or HTML via the callback parameter, a related issue to CVE-2013-7341.

    Published: 22 Mar 2014
    4.9
    Medium

    CVE-2014-0123

    Last Modified: 12 Apr 2025

    The wiki subsystem in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 does not properly restrict (1) view and (2) edit access, which allows remote authenticated users to perform wiki operations by leveraging the student role and using the Recent Activity block to reach the individual wiki of an arbitrary student.

    Published: 22 Mar 2014
    4.9
    Medium

    CVE-2014-0127

    Last Modified: 12 Apr 2025

    The time-validation implementation in (1) mod/feedback/complete.php and (2) mod/feedback/complete_guest.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote authenticated users to bypass intended restrictions on starting a Feedback activity by choosing an unavailable time.

    Published: 22 Mar 2014
    8.3
    High

    CVE-2014-2250

    Last Modified: 12 Apr 2025

    The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors, a different vulnerability than CVE-2014-2251.

    Published: 22 Mar 2014
    5
    Medium

    CVE-2014-2276

    Last Modified: 12 Apr 2025

    The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not properly restrict additions to the Connectrix Manager repository, which allows remote attackers to obtain sensitive information by importing a crafted firmware file.

    Published: 21 Mar 2014
    3.5
    Low

    CVE-2013-6729

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM QuickFile 1.0.0.0 before iFix 4 and 1.1.0.1 before iFix 3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 21 Mar 2014
    9.3
    Critical

    CVE-2014-0879

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the Taskmaster Capture ActiveX control in IBM Datacap Taskmaster Capture 8.0.1, and 8.1 before FP2, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 21 Mar 2014
    5
    Medium

    CVE-2013-5401

    Last Modified: 12 Apr 2025

    The command-port listener in IBM WebSphere MQ Internet Pass-Thru (MQIPT) 2.x before 2.1.0.1 allows remote attackers to cause a denial of service (remote-administration outage) via unspecified vectors.

    Published: 21 Mar 2014
    6.5
    Medium

    CVE-2014-0829

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in IBM Rational ClearCase 7.x before 7.1.2.13, 8.0.0.x before 8.0.0.10, and 8.0.1.x before 8.0.1.3 allow remote authenticated users to obtain privileged access via unspecified vectors.

    Published: 21 Mar 2014
    4.3
    Medium

    CVE-2014-2567

    Last Modified: 12 Apr 2025

    The OpenConnectionTask::handleStateHelper function in Imap/Tasks/OpenConnectionTask.cpp in Trojita before 0.4.1 allows man-in-the-middle attackers to trigger use of cleartext for saving a message into a (1) sent or (2) draft folder via a PREAUTH response that prevents later use of the STARTTLS command.

    Published: 21 Mar 2014
    9.8
    Critical

    CVE-2013-4486

    Last Modified: 21 Nov 2024

    Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging

    Published: 21 Mar 2014
    5
    Medium

    CVE-2014-0708

    Last Modified: 12 Apr 2025

    WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) a browser's history, aka Bug ID CSCul98272.

    Published: 20 Mar 2014
    7.1
    High

    CVE-2014-2124

    Last Modified: 12 Apr 2025

    Cisco IOS 15.1(2)SY3 and earlier, when used with Supervisor Engine 2T (aka Sup2T) on Catalyst 6500 devices, allows remote attackers to cause a denial of service (device crash) via crafted multicast packets, aka Bug ID CSCuf60783.

    Published: 20 Mar 2014
    8.5
    High

    CVE-2014-2119

    Last Modified: 12 Apr 2025

    The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 allows remote authenticated users to execute arbitrary code with root privileges via an FTP session that uploads a modified SLBL database file, aka Bug IDs CSCug79377 and CSCug80118.

    Published: 20 Mar 2014
    4.3
    Medium

    CVE-2013-7340

    Last Modified: 12 Apr 2025

    VideoLAN VLC Media Player before 2.0.7 allows remote attackers to cause a denial of service (memory consumption) via a crafted playlist file.

    Published: 20 Mar 2014
    2.1
    Low

    CVE-2011-3196

    Last Modified: 12 Apr 2025

    The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable permissions for /etc/apache2/apache2.conf, which allows local users to obtain the dtcdaemons MySQL password by reading the file.

    Published: 20 Mar 2014
    2.1
    Low

    CVE-2011-3198

    Last Modified: 12 Apr 2025

    Domain Technologie Control (DTC) before 0.34.1 includes a password in the -b command line argument to htpasswd, which might allow local users to read the password by listing the process and its arguments.

    Published: 20 Mar 2014
    3.5
    Low

    CVE-2011-3199

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0.34.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message body of a support ticket or unspecified vectors to the (2) DNS and (3) MX form, as demonstrated by the "Domain root TXT record:" field.

    Published: 20 Mar 2014
    6.5
    Medium

    CVE-2011-5272

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the vps_note parameter to dtcadmin/logPushlet.php. NOTE: this issue was originally part of CVE-2011-3197, but that ID was SPLIT due to different researchers.

    Published: 20 Mar 2014
    6.5
    Medium

    CVE-2011-5273

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the pkg parameter in a do_install action to dtc/.

    Published: 20 Mar 2014
    7.5
    High

    CVE-2011-5274

    Last Modified: 12 Apr 2025

    The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the dtcpkg_directory parameter in a do_install action to dtc/.

    Published: 20 Mar 2014
    7.5
    High

    CVE-2011-5275

    Last Modified: 12 Apr 2025

    The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for context-dependent users to gain privileges.

    Published: 20 Mar 2014
    6.5
    Medium

    CVE-2011-5276

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote authenticated users to execute arbitrary SQL commands via the database_name parameter.

    Published: 20 Mar 2014
    6.5
    Medium

    CVE-2011-3195

    Last Modified: 12 Apr 2025

    shared/inc/sql/lists.php in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in mailing list tunable options.

    Published: 20 Mar 2014
    6.5
    Medium

    CVE-2011-3197

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the addrlink parameter to shared/inc/forms/domain_info.php. NOTE: CVE-2011-3197 has been SPLIT due to findings by different researchers. CVE-2011-5272 has been assigned for the vps_note parameter to dtcadmin/logPushlet.php vector.

    Published: 20 Mar 2014
    4.3
    Medium

    CVE-2014-2280

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the search feature in SeedDMS (formerly LetoDMS and MyDMS) before 4.3.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 20 Mar 2014
    4.3
    Medium

    CVE-2013-0805

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the search feature in iTop (aka IT Operations Portal) 2.0, 1.2.1, 1.2, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to pages/UI.php or (2) expression parameter to pages/run_query.php. NOTE: some of these details are obtained from third party information.

    Published: 20 Mar 2014
    9.3
    Critical

    CVE-2013-3249

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372, 9.0.1.247, and earlier allows user-assisted attackers to execute arbitrary code via unspecified vectors.

    Published: 20 Mar 2014
    4.3
    Medium

    CVE-2014-2077

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 7.4.1 before 7.4.1-rev10 and 7.4.2 before 7.4.2-rev8 allows remote attackers to inject arbitrary web script or HTML via the subject of an email, involving 'the aria "tags" for screenreaders at the top bar'.

    Published: 20 Mar 2014
    4.3
    Medium

    CVE-2014-2219

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in whizzywig/wb.php in CMSimple Classic 3.54 and earlier, possibly as downloaded before February 26, 2014, allows remote attackers to inject arbitrary web script or HTML via the d parameter.

    Published: 20 Mar 2014
    7.5
    High

    CVE-2014-1609

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in api/soap/mc_project_api.php; the (2) news_get_limited_rows function in core/news_api.php; the (3) summary_print_by_enum, (4) summary_print_by_age, (5) summary_print_by_developer, (6) summary_print_by_reporter, or (7) summary_print_by_category function in core/summary_api.php; the (8) create_bug_enum_summary or (9) enum_bug_group function in plugins/MantisGraph/core/graph_api.php; (10) bug_graph_bycategory.php or (11) bug_graph_bystatus.php in plugins/MantisGraph/pages/; or (12) proj_doc_page.php, related to use of the db_query function, a different vulnerability than CVE-2014-1608.

    Published: 20 Mar 2014
    5.8
    Medium

    CVE-2014-1970

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the ES File Explorer File Manager application before 3.0.4 for Android allows remote attackers to overwrite or create arbitrary files via unspecified vectors.

    Published: 20 Mar 2014
    4.3
    Medium

    CVE-2014-1971

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Silex before 2.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Mar 2014