CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2014-1514

    Last Modified: 25 Nov 2025

    vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by triggering incorrect use of the TypedArrayObject class.

    Published: 18 Mar 2014
    9.3
    Critical

    CVE-2014-1494

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 18 Mar 2014
    5.5
    Medium

    CVE-2014-1496

    Last Modified: 25 Nov 2025

    Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.

    Published: 18 Mar 2014
    5
    Medium

    CVE-2014-1498

    Last Modified: 12 Apr 2025

    The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.

    Published: 18 Mar 2014
    6.8
    Medium

    CVE-2014-0152

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in the web admin interface in oVirt 3.4.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 17 Mar 2014
    4.3
    Medium

    CVE-2014-0153

    Last Modified: 12 Apr 2025

    The REST API in oVirt 3.4.0 and earlier stores session IDs in HTML5 local storage, which allows remote attackers to obtain sensitive information via a crafted web page.

    Published: 17 Mar 2014
    5
    Medium

    CVE-2014-0154

    Last Modified: 12 Apr 2025

    oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 17 Mar 2014
    6.8
    Medium

    CVE-2014-0151

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in oVirt Engine before 3.5.0 beta2 allows remote attackers to hijack the authentication of users for requests that perform unspecified actions via a REST API request.

    Published: 17 Mar 2014
    6.5
    Medium

    CVE-2013-4058

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote authenticated users to execute arbitrary SQL commands via unspecified interfaces.

    Published: 16 Mar 2014
    4.3
    Medium

    CVE-2013-4059

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server 8.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified interfaces.

    Published: 16 Mar 2014
    7.2
    High

    CVE-2013-6208

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Smart Update Manager 5.3.5 before build 70 on Linux allows local users to gain privileges via unknown vectors.

    Published: 16 Mar 2014
    4.3
    Medium

    CVE-2014-1701

    Last Modified: 12 Apr 2025

    The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1710

    Last Modified: 12 Apr 2025

    The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS before 33.0.1750.152, does not check whether a certain position is within the bounds of a shared-memory segment, which allows remote attackers to cause a denial of service (GPU command-buffer memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1713

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp in the bindings in Blink, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the document.location value.

    Published: 16 Mar 2014
    5.8
    Medium

    CVE-2014-2249

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 and SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 16 Mar 2014
    4.3
    Medium

    CVE-2014-2246

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Mar 2014
    5.8
    Medium

    CVE-2014-2247

    Last Modified: 12 Apr 2025

    The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject headers via unspecified vectors.

    Published: 16 Mar 2014
    6.1
    Medium

    CVE-2014-2253

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted Profinet packets.

    Published: 16 Mar 2014
    7.8
    High

    CVE-2014-2255

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTP packets.

    Published: 16 Mar 2014
    7.8
    High

    CVE-2014-2257

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted ISO-TSAP packets.

    Published: 16 Mar 2014
    7.8
    High

    CVE-2014-2259

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTPS packets.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2013-6210

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Unified Functional Testing before 12.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1932.

    Published: 16 Mar 2014
    4.3
    Medium

    CVE-2014-0338

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the pol_name parameter.

    Published: 16 Mar 2014
    4.3
    Medium

    CVE-2014-0339

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in view.cgi in Webmin before 1.680 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 16 Mar 2014
    6.8
    Medium

    CVE-2014-0873

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Data Stewardship, (2) Business Admin, and (3) Product interfaces in IBM InfoSphere Master Data Management (MDM) Server 8.5 before 8.5.0.82, 9.0.1 before 9.0.1.38, 9.0.2 before 9.0.2.35, 10.0 before 10.0.0.0.26, and 10.1 before 10.1.0.0.15 allow remote attackers to hijack the authentication of arbitrary users.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-0895

    Last Modified: 12 Apr 2025

    Buffer overflow in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 3.0.1-IM-S3SAMPC-WIN32-FP001-IF02 allows remote attackers to execute arbitrary code via a crafted ComboList property value.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1700

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in modules/speech/SpeechSynthesis.cpp in Blink, as used in Google Chrome before 33.0.1750.149, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of a certain utterance data structure.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1703

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the WebSocketDispatcherHost::SendOrDrop function in content/browser/renderer_host/websocket_dispatcher_host.cc in the Web Sockets implementation in Google Chrome before 33.0.1750.149 might allow remote attackers to bypass the sandbox protection mechanism by leveraging an incorrect deletion in a certain failure case.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1706

    Last Modified: 12 Apr 2025

    crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1707

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecified impact and attack vectors.

    Published: 16 Mar 2014
    10
    Critical

    CVE-2014-1708

    Last Modified: 12 Apr 2025

    The boot implementation in Google Chrome OS before 33.0.1750.152 does not properly consider file persistence, which allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1714

    Last Modified: 12 Apr 2025

    The ScopedClipboardWriter::WritePickledData function in ui/base/clipboard/scoped_clipboard_writer.cc in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows does not verify a certain format value, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the clipboard.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1715

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact and attack vectors.

    Published: 16 Mar 2014
    6.8
    Medium

    CVE-2013-4057

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the XML Pack in IBM InfoSphere Information Server 8.5.x through 8.5 FP3, 8.7.x through 8.7 FP2, and 9.1.x through 9.1.2.0 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 16 Mar 2014
    3.5
    Low

    CVE-2014-0850

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Reference Data Management (RDM) Hub 10.1 and 11.0 before 11.0.0.0-MDM-IF008 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1702

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the DatabaseThread::cleanupDatabaseThread function in modules/webdatabase/DatabaseThread.cpp in the web database implementation in Blink, as used in Google Chrome before 33.0.1750.149, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of scheduled tasks during shutdown of a thread.

    Published: 16 Mar 2014
    7.5
    High

    CVE-2014-1711

    Last Modified: 12 Apr 2025

    The GPU driver in the kernel in Google Chrome OS before 33.0.1750.152 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.

    Published: 16 Mar 2014
    4.3
    Medium

    CVE-2014-2248

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 16 Mar 2014
    8.3
    High

    CVE-2014-2251

    Last Modified: 12 Apr 2025

    The random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors.

    Published: 16 Mar 2014
    4.2
    Medium

    CVE-2014-2532

    Last Modified: 28 May 2026

    sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

    Published: 15 Mar 2014
    6.8
    Medium

    CVE-2013-0301

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in apps/calendar/ajax/settings/settimezone in ownCloud before 4.0.12 allows remote attackers to hijack the authentication of users for requests that change the timezone via the timezone parameter.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2013-0299

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote attackers to hijack the authentication of users for requests that (1) change the timezone for the user via the lat and lng parameters to apps/calendar/ajax/settings/guesstimezone.php, (2) disable or enable the automatic timezone detection via the timezonedetection parameter to apps/calendar/ajax/settings/timezonedetection.php, (3) import user accounts via the admin_export parameter to apps/admin_migrate/settings.php, (4) overwrite user files via the operation parameter to apps/user_migrate/ajax/export.php, or (5) change the authentication server URL via unspecified vectors to apps/user_ldap/settings.php.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2013-0300

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to hijack the authentication of users for requests that (1) change the default view via the v parameter to apps/calendar/ajax/changeview.php, mount arbitrary (2) Google Drive or (3) Dropbox folders via vectors related to addRootCertificate.php, dropbox.php and google.php in apps/files_external/ajax/, or (4) change the authentication server URL via unspecified vectors to apps/user_webdavauth/settings.php.

    Published: 14 Mar 2014
    3.5
    Low

    CVE-2013-2042

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the url parameter to (1) apps/bookmarks/ajax/addBookmark.php or (2) apps/bookmarks/ajax/editBookmark.php.

    Published: 14 Mar 2014
    2.1
    Low

    CVE-2013-2047

    Last Modified: 12 Apr 2025

    The login page (aka index.php) in ownCloud before 5.0.6 does not disable the autocomplete setting for the password parameter, which makes it easier for physically proximate attackers to guess the password.

    Published: 14 Mar 2014
    6.5
    Medium

    CVE-2013-2048

    Last Modified: 12 Apr 2025

    ownCloud before 5.0.6 does not properly check permissions, which allows remote authenticated users to execute arbitrary API commands via unspecified vectors. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary API commands.

    Published: 14 Mar 2014
    4
    Medium

    CVE-2013-2085

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in apps/files_trashbin/index.php in ownCloud Server before 5.0.6 allows remote authenticated users to access arbitrary files via a .. (dot dot) in the dir parameter.

    Published: 14 Mar 2014
    3.5
    Low

    CVE-2013-2149

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.16 and 5.x before 5.0.7 allow remote authenticated users to inject arbitrary web script or HTML via vectors related to shared files.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2012-0891

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Puppet Dashboard 1.0 before 1.2.5 and Enterprise 1.0 before 1.2.5 and 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified fields.

    Published: 14 Mar 2014
    4
    Medium

    CVE-2012-5158

    Last Modified: 12 Apr 2025

    Puppet Enterprise (PE) before 2.6.1 does not properly invalidate sessions when the session secret has changed, which allows remote authenticated users to retain access via unspecified vectors.

    Published: 14 Mar 2014