CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2014-1716

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Runtime_SetPrototype function in runtime.cc in Google V8, as used in Google Chrome before 34.0.1847.116, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)."

    Published: 20 Mar 2014
    4.3
    Medium

    CVE-2013-5952

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) xhash parameter to client/chat.php or (3) toname parameter to client/plugins/upload/upload.php.

    Published: 19 Mar 2014
    4.3
    Medium

    CVE-2013-5953

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in tmpl/layout_editevent.php in the Multi Calendar (com_multicalendar) component 4.0.2, and possibly 4.8.5 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) calid or (2) paletteDefault parameter in an editevent action to index.php.

    Published: 19 Mar 2014
    6.5
    Medium

    CVE-2014-2339

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in bbs/ajax.autosave.php in GNUboard 5.x and possibly earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) subject or (2) content parameter.

    Published: 19 Mar 2014
    4.3
    Medium

    CVE-2014-1978

    Last Modified: 12 Apr 2025

    The application link interface in the NTT DOCOMO sp mode mail application 6100 through 6300 for Android 4.0.x and 6130 through 6700 for Android 4.1 through 4.4 writes message content to the SD card during e-mail composition, which allows attackers to obtain sensitive information via a crafted application.

    Published: 19 Mar 2014
    6.8
    Medium

    CVE-2014-1979

    Last Modified: 12 Apr 2025

    The NTT DOCOMO sp mode mail application 5900 through 6300 for Android 4.0.x and 6000 through 6620 for Android 4.1 through 4.4 allows remote attackers to execute arbitrary Java methods via Deco-mail emoticon POP data in an e-mail message.

    Published: 19 Mar 2014
    4.3
    Medium

    CVE-2013-5955

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in manage.php in the PBBooking (com_pbbooking) component 2.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the an arbitrary parameter in an edit action to administrator/index.php.

    Published: 19 Mar 2014
    4.3
    Medium

    CVE-2014-1977

    Last Modified: 12 Apr 2025

    The NTT DOCOMO sp mode mail application 6300 and earlier for Android 4.0.x and 6700 and earlier for Android 4.1 through 4.4 uses weak permissions for attachments during processing of incoming e-mail messages, which allows attackers to obtain sensitive information via a crafted application.

    Published: 19 Mar 2014
    6.4
    Medium

    CVE-2014-1506

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.

    Published: 19 Mar 2014
    5.8
    Medium

    CVE-2014-1501

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.

    Published: 19 Mar 2014
    9.3
    Critical

    CVE-2014-1507

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.

    Published: 19 Mar 2014
    6.1
    Medium

    CVE-2014-2120

    Last Modified: 21 Apr 2026

    Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.

    Published: 19 Mar 2014
    5
    Medium

    CVE-2014-2121

    Last Modified: 12 Apr 2025

    The Java-based software in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (closing of TCP ports) via unspecified vectors, aka Bug IDs CSCug77633, CSCug77667, CSCug78266, CSCug82795, and CSCuh58643.

    Published: 19 Mar 2014
    5
    Medium

    CVE-2014-2122

    Last Modified: 12 Apr 2025

    Memory leak in the GUI in the Impact server in Cisco Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, aka Bug ID CSCub58999.

    Published: 19 Mar 2014
    9.8
    Critical

    CVE-2014-0011

    Last Modified: 21 Nov 2024

    Multiple heap-based buffer overflows in the ZRLE_DECODE function in common/rfb/zrleDecode.h in TigerVNC before 1.3.1, when NDEBUG is enabled, allow remote VNC servers to cause a denial of service (vncviewer crash) and possibly execute arbitrary code via vectors related to screen image rendering.

    Published: 19 Mar 2014
    4.3
    Medium

    CVE-2013-0201

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to core/lostpassword/templates/resetpassword.php, (2) mime parameter to apps/files/ajax/mimeicon.php, or (3) token parameter to apps/gallery/sharing.php.

    Published: 18 Mar 2014
    9.3
    Critical

    CVE-2013-3938

    Last Modified: 12 Apr 2025

    Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buffer overflow.

    Published: 18 Mar 2014
    7.5
    High

    CVE-2014-1608

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the mci_file_get function in api/soap/mc_file_api.php in MantisBT before 1.2.16 allows remote attackers to execute arbitrary SQL commands via a crafted envelope tag in a mc_issue_attachment_get SOAP request.

    Published: 18 Mar 2014
    7.8
    High

    CVE-2014-2537

    Last Modified: 12 Apr 2025

    Memory leak in the TCP stack in the kernel in Sophos UTM before 9.109 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

    Published: 18 Mar 2014
    5
    Medium

    CVE-2012-5641

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the default URI.

    Published: 18 Mar 2014
    5
    Medium

    CVE-2013-2619

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a .. (dot dot) to the default URI.

    Published: 18 Mar 2014
    5
    Medium

    CVE-2013-2641

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.

    Published: 18 Mar 2014
    4.3
    Medium

    CVE-2013-2643

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action to rss.php, (2) msg parameter to end-user/errdoc.php, (3) h parameter to end-user/ftp_redirect.php, or (4) threat parameter to the Blocked component.

    Published: 18 Mar 2014
    9.3
    Critical

    CVE-2014-2087

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download queue by the user.

    Published: 18 Mar 2014
    4
    Medium

    CVE-2014-2535

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in McAfee Web Gateway (MWG) 7.4.x before 7.4.1, 7.3.x before 7.3.2.6, and 7.2.0.9 and earlier allows remote authenticated users to read arbitrary files via a crafted request to the web filtering port.

    Published: 18 Mar 2014
    4.3
    Medium

    CVE-2012-5650

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite.

    Published: 18 Mar 2014
    9.3
    Critical

    CVE-2013-2642

    Last Modified: 12 Apr 2025

    Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation variable in a customized template, and remote authenticated users to execute arbitrary commands via shell metacharacters in the (2) url parameter to the Diagnostic Tools functionality or (3) entries parameter to the Local Site List functionality.

    Published: 18 Mar 2014
    4.3
    Medium

    CVE-2014-2536

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown vectors.

    Published: 18 Mar 2014
    5.8
    Medium

    CVE-2014-1975

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the R-Company Unzipper application 1.0.1 and earlier for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename.

    Published: 18 Mar 2014
    5.8
    Medium

    CVE-2014-1976

    Last Modified: 12 Apr 2025

    The Demaecan application 2.1.0 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 18 Mar 2014
    7.2
    High

    CVE-2014-2533

    Last Modified: 12 Apr 2025

    /sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument.

    Published: 18 Mar 2014
    4.9
    Medium

    CVE-2014-2534

    Last Modified: 12 Apr 2025

    /sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow.

    Published: 18 Mar 2014
    8.8
    High

    CVE-2014-1513

    Last Modified: 25 Nov 2025

    TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based out-of-bounds write or read) via a crafted web site.

    Published: 18 Mar 2014
    9.8
    Critical

    CVE-2014-1511

    Last Modified: 25 Nov 2025

    Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.

    Published: 18 Mar 2014
    9.8
    Critical

    CVE-2014-1510

    Last Modified: 25 Nov 2025

    The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.

    Published: 18 Mar 2014
    8.8
    High

    CVE-2014-1509

    Last Modified: 25 Nov 2025

    Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document.

    Published: 18 Mar 2014
    9.1
    Critical

    CVE-2014-1508

    Last Modified: 25 Nov 2025

    The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via vectors involving MathML polygon rendering.

    Published: 18 Mar 2014
    7.5
    High

    CVE-2014-1505

    Last Modified: 25 Nov 2025

    The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements, a related issue to CVE-2013-1693.

    Published: 18 Mar 2014
    8.8
    High

    CVE-2014-1497

    Last Modified: 25 Nov 2025

    The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impact via a crafted WAV file.

    Published: 18 Mar 2014
    9.8
    Critical

    CVE-2014-1493

    Last Modified: 25 Nov 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 18 Mar 2014
    7.5
    High

    CVE-2014-1717

    Last Modified: 12 Apr 2025

    Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 18 Mar 2014
    10
    Critical

    CVE-2014-1512

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is occurring, as demonstrated by improper handling of BumpChunk objects.

    Published: 18 Mar 2014
    5
    Medium

    CVE-2014-1500

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.

    Published: 18 Mar 2014
    2.9
    Low

    CVE-2014-2568

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.

    Published: 18 Mar 2014
    4
    Medium

    CVE-2014-3940

    Last Modified: 12 Apr 2025

    The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.

    Published: 18 Mar 2014
    7.5
    High

    CVE-2014-0133

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.

    Published: 18 Mar 2014
    4.3
    Medium

    CVE-2014-1492

    Last Modified: 12 Apr 2025

    The cert_TestHostName function in lib/certdb/certdb.c in the certificate-checking implementation in Mozilla Network Security Services (NSS) before 3.16 accepts a wildcard character that is embedded in an internationalized domain name's U-label, which might allow man-in-the-middle attackers to spoof SSL servers via a crafted certificate.

    Published: 18 Mar 2014
    4.3
    Medium

    CVE-2014-1499

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.

    Published: 18 Mar 2014
    6.8
    Medium

    CVE-2014-1502

    Last Modified: 12 Apr 2025

    The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.

    Published: 18 Mar 2014
    2.6
    Low

    CVE-2014-1504

    Last Modified: 12 Apr 2025

    The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.

    Published: 18 Mar 2014