CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2013-1398

    Last Modified: 12 Apr 2025

    The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obtain sensitive information and gain privileges by leveraging root access to a node, related to the master role.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2013-1399

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) node request management, (2) live management, and (3) user administration components in the console in Puppet Enterprise (PE) before 2.7.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 14 Mar 2014
    2.1
    Low

    CVE-2013-1822

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.8 allow remote authenticated users with administrator privileges to inject arbitrary web script or HTML via the (1) quota parameter to /core/settings/ajax/setquota.php, or remote authenticated users with group admin privileges to inject arbitrary web script or HTML via the (2) group field to settings.php or (3) "share with" field.

    Published: 14 Mar 2014
    6.5
    Medium

    CVE-2013-1850

    Last Modified: 12 Apr 2025

    Multiple incomplete blacklist vulnerabilities in (1) import.php and (2) ajax/uploadimport.php in apps/contacts/ in ownCloud before 4.0.13 and 4.5.x before 4.5.8 allow remote authenticated users to execute arbitrary PHP code by uploading a .htaccess file.

    Published: 14 Mar 2014
    4
    Medium

    CVE-2013-1963

    Last Modified: 12 Apr 2025

    The contacts application in ownCloud before 4.5.10 and 5.x before 5.0.5 does not properly check the ownership of contacts, which allows remote authenticated users to download arbitrary contacts via unspecified vectors.

    Published: 14 Mar 2014
    4
    Medium

    CVE-2013-2039

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in lib/files/view.php in ownCloud before 4.0.15, 4.5.x 4.5.11, and 5.x before 5.0.6 allows remote authenticated users to access arbitrary files via unspecified vectors.

    Published: 14 Mar 2014
    3.5
    Low

    CVE-2013-2040

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.15, 4.5.x before 4.5.11, and 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Mar 2014
    3.5
    Low

    CVE-2013-2041

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 5.0.x before 5.0.6 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tag parameter to apps/bookmarks/ajax/addBookmark.php or (2) dir parameter to apps/files/ajax/newfile.php, which is passed to apps/files/js/files.js.

    Published: 14 Mar 2014
    4
    Medium

    CVE-2013-2043

    Last Modified: 12 Apr 2025

    apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calendars via the calendar_id parameter.

    Published: 14 Mar 2014
    5.8
    Medium

    CVE-2013-2044

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

    Published: 14 Mar 2014
    3.5
    Low

    CVE-2013-2150

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in ownCloud before 4.5.12 and 5.x before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to shared files.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2014-2047

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2014-2049

    Last Modified: 12 Apr 2025

    The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified vectors.

    Published: 14 Mar 2014
    3.5
    Low

    CVE-2013-1851

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.13 and 4.5.x before 4.5.8, when the user_migrate application is enabled, allows remote authenticated users to import arbitrary files to the user's account via unspecified vectors.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2013-1939

    Last Modified: 12 Apr 2025

    The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a \ (backslash) character.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2013-2086

    Last Modified: 12 Apr 2025

    The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an unspecified JavaScript file.

    Published: 14 Mar 2014
    4.6
    Medium

    CVE-2013-2089

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the file in /data.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2013-4963

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Puppet Enterprise (PE) before 3.0.1 allow remote attackers to hijack the authentication of users for requests that deleting a (1) report, (2) group, or (3) class or possibly have other unspecified impact.

    Published: 14 Mar 2014
    3.5
    Low

    CVE-2013-0297

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) site_name or (2) site_url parameter to apps/external/ajax/setsites.php.

    Published: 14 Mar 2014
    3.5
    Low

    CVE-2014-2291

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Mar 2014
    7.2
    High

    CVE-2014-2292

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Linux Network Connect client in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows local users to gain privileges via unspecified vectors.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2014-2324

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2013-0298

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted iCalendar file to the calendar application, the (2) dir or (3) file parameter to apps/files_pdfviewer/viewer.php, or the (4) mountpoint parameter to /apps/files_external/addMountPoint.php.

    Published: 14 Mar 2014
    3.5
    Low

    CVE-2013-0307

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field parameter.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2013-6474

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.

    Published: 14 Mar 2014
    4.4
    Medium

    CVE-2013-6476

    Last Modified: 12 Apr 2025

    The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2013-6473

    Last Modified: 12 Apr 2025

    Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.

    Published: 14 Mar 2014
    9.8
    Critical

    CVE-2014-2323

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2013-2507

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Brother MFC-9970CDW printer with firmware G (1.03) allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/log_to_net.html or (2) kind parameter to fax/copy_settings.html, a different vulnerability than CVE-2013-2670 and CVE-2013-2671.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2014-2325

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway before 3.1-5829 allow remote attackers to inject arbitrary web script or HTML via the (1) state parameter to objects/who/index.htm or (2) User email address to quarantine/spam/manage.htm.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2013-1758

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Marekkis Watermark plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pfad parameter to wp-admin/options-general.php. NOTE: some of these details are obtained from third party information.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2013-1759

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Responsive Logo Slideshow plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the "URL and Image" field.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2013-2670

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Brother MFC-9970CDW printer with firmware G (1.03) and L (1.10) allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter name (QUERY_STRING) to admin/admin_main.html, a different vulnerability than CVE-2013-2507 and CVE-2013-2671.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2013-2671

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Brother MFC-9970CDW printer with firmware L (1.10) allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) val parameter to admin/admin_main.html; (3) id, (4) val, or (5) arbitrary parameter name (QUERY_STRING) to admin/profile_settings_net.html; or (6) kind or (7) arbitrary parameter name (QUERY_STRING) to fax/general_setup.html, a different vulnerability than CVE-2013-2507 and CVE-2013-2670.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2014-2024

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-apartments-rooms/.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2013-6835

    Last Modified: 12 Apr 2025

    TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote attackers to obtain telephone number or e-mail address information via a facetime-audio: URL.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2014-0694

    Last Modified: 12 Apr 2025

    Intelligent Automation for Cloud (IAC) in Cisco Cloud Portal 9.4.1 and earlier includes a cryptographic key in binary files, which makes it easier for remote attackers to obtain cleartext data from an arbitrary IAC installation by leveraging knowledge of this key, aka Bug IDs CSCui34764, CSCui34772, CSCui34776, CSCui34798, CSCui34800, CSCui34805, CSCui34809, CSCui34810, CSCui34813, CSCui34814, and CSCui34818.

    Published: 14 Mar 2014
    5.8
    Medium

    CVE-2014-1285

    Last Modified: 12 Apr 2025

    Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveraging an application crash during activation of an unactivated device.

    Published: 14 Mar 2014
    7.2
    High

    CVE-2014-1287

    Last Modified: 12 Apr 2025

    USB Host in Apple iOS before 7.1 and Apple TV before 6.1 allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted USB messages.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2014-1290

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2014-1292

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1293, and CVE-2014-1294.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2014-2265

    Last Modified: 12 Apr 2025

    Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 parameter.

    Published: 14 Mar 2014
    5.8
    Medium

    CVE-2014-1273

    Last Modified: 12 Apr 2025

    dyld in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass code-signing requirements by leveraging use of text-relocation instructions in a dynamic library.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2014-2319

    Last Modified: 12 Apr 2025

    The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which makes it easier for context-dependent attackers to obtain sensitive information via a known-plaintext attack.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2013-4846

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP System Management Homepage (SMH) before 7.3 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 14 Mar 2014
    8.8
    High

    CVE-2013-5133

    Last Modified: 12 Apr 2025

    Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via crafted backup data.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2013-6188

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) 7.1 through 7.2.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 14 Mar 2014
    4.1
    Medium

    CVE-2013-6205

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Rapid Deployment Pack (RDP) and Insight Control Server Deployment allows local users to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

    Published: 14 Mar 2014
    9
    Critical

    CVE-2013-6206

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Rapid Deployment Pack (RDP) and Insight Control Server Deployment allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

    Published: 14 Mar 2014
    10
    Critical

    CVE-2014-0505

    Last Modified: 12 Apr 2025

    Adobe Shockwave Player before 12.1.0.150 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 14 Mar 2014