CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2014-1271

    Last Modified: 12 Apr 2025

    CoreCapture in Apple iOS before 7.1 and Apple TV before 6.1 does not properly validate IOKit API calls, which allows attackers to cause a denial of service (assertion failure and device crash) via a crafted app.

    Published: 14 Mar 2014
    6.3
    Medium

    CVE-2014-1272

    Last Modified: 12 Apr 2025

    CrashHouseKeeping in Crash Reporting in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to change arbitrary file permissions by leveraging a symlink.

    Published: 14 Mar 2014
    2.1
    Low

    CVE-2014-1274

    Last Modified: 12 Apr 2025

    FaceTime in Apple iOS before 7.1 allows physically proximate attackers to obtain sensitive FaceTime contact information by using the lock screen for an invalid FaceTime call.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2014-1275

    Last Modified: 12 Apr 2025

    Buffer overflow in ImageIO in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.

    Published: 14 Mar 2014
    7.2
    High

    CVE-2014-1278

    Last Modified: 12 Apr 2025

    The ptmx_get_ioctl function in the ARM kernel in Apple iOS before 7.1 and Apple TV before 6.1 allows local users to gain privileges or cause a denial of service (out-of-bounds memory access and device crash) via a crafted call.

    Published: 14 Mar 2014
    2.1
    Low

    CVE-2014-1279

    Last Modified: 12 Apr 2025

    Apple TV before 6.1 does not properly restrict logging, which allows local users to obtain sensitive information by reading log data.

    Published: 14 Mar 2014
    7.1
    High

    CVE-2014-1280

    Last Modified: 12 Apr 2025

    Video Driver in Apple iOS before 7.1 and Apple TV before 6.1 allows remote attackers to cause a denial of service (NULL pointer dereference and device hang) via a crafted video file with MPEG-4 encoding.

    Published: 14 Mar 2014
    1.9
    Low

    CVE-2014-1281

    Last Modified: 12 Apr 2025

    Photos Backend in Apple iOS before 7.1 does not properly manage the asset-library cache during deletions, which allows physically proximate attackers to obtain sensitive photo data by launching the Photos app and looking under a transparent image.

    Published: 14 Mar 2014
    5.8
    Medium

    CVE-2014-1282

    Last Modified: 12 Apr 2025

    The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requirements via a long name.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2014-1286

    Last Modified: 12 Apr 2025

    SpringBoard Lock Screen in Apple iOS before 7.1 allows remote attackers to cause a denial of service (lock-screen hang) by leveraging a state-management error.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2014-1289

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2014-1291

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1292, CVE-2014-1293, and CVE-2014-1294.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2014-1294

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1293.

    Published: 14 Mar 2014
    4.3
    Medium

    CVE-2013-6209

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in rpc.lockd in the NFS subsystem in HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2014-0779

    Last Modified: 24 Sept 2025

    The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4165, 2010 R2.1 build 71.4325, 2010 R3 build 72.4560, 2010 R3.1 build 72.4644, 2013 R1 build 73.4729, 2013 R1.1 build 73.4832, 2013 R1.1a build 73.4903, 2013 R1.2 build 73.4955, and 2013 R2 build 74.5094 allows remote attackers to cause a denial of service (application crash) via a crafted OPF file (aka project file).

    Published: 14 Mar 2014
    9
    Critical

    CVE-2014-0783

    Last Modified: 25 Sept 2025

    Stack-based buffer overflow in BKHOdeq.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

    Published: 14 Mar 2014
    5.8
    Medium

    CVE-2014-1267

    Last Modified: 12 Apr 2025

    The Configuration Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 does not properly evaluate the expiration date of a mobile configuration profile, which allows attackers to bypass intended access restrictions by using a profile after the date has passed.

    Published: 14 Mar 2014
    5
    Medium

    CVE-2014-1276

    Last Modified: 12 Apr 2025

    IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that accesses an IOKit framework interface.

    Published: 14 Mar 2014
    6.8
    Medium

    CVE-2014-1293

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 7.1 and Apple TV before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1289, CVE-2014-1290, CVE-2014-1291, CVE-2014-1292, and CVE-2014-1294.

    Published: 14 Mar 2014
    9.3
    Critical

    CVE-2014-0781

    Last Modified: 25 Sept 2025

    Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via crafted UDP packets.

    Published: 14 Mar 2014
    8.3
    High

    CVE-2014-0784

    Last Modified: 25 Sept 2025

    Stack-based buffer overflow in BKBCopyD.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via a crafted TCP packet.

    Published: 14 Mar 2014
    7.5
    High

    CVE-2014-1705

    Last Modified: 12 Apr 2025

    Google V8, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 14 Mar 2014
    3.3
    Low

    CVE-2014-2524

    Last Modified: 12 Apr 2025

    The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.

    Published: 14 Mar 2014
    6.5
    Medium

    CVE-2014-2043

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to execute arbitrary SQL commands via the value parameter.

    Published: 13 Mar 2014
    7.5
    High

    CVE-2013-3727

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parameter to admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

    Published: 13 Mar 2014
    3.5
    Low

    CVE-2013-3728

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users with permissions to create categories to inject arbitrary web script or HTML via the cat parameter in an admin_new_category action to admin.php.

    Published: 13 Mar 2014
    6.8
    Medium

    CVE-2013-3729

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Kasseler CMS before 2 r1232 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) groups[] parameter in a send action in the sendmail module or (2) query parameter in a sql_query action in the database module to admin.php, related to CVE-2013-3727.

    Published: 13 Mar 2014
    4.3
    Medium

    CVE-2014-1877

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Phone, (2) Street, (3) Address line, (4) Zip code, or (5) City field to main/auth/profile.php; (6) Subject field to main/social/groups.php; or (7) Message body field to main/messages/view_message.php.

    Published: 13 Mar 2014
    Unknown

    CVE-2014-1284

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-2019. Reason: This candidate is a duplicate of CVE-2014-2019. Notes: All CVE users should reference CVE-2014-2019 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Mar 2014
    Unknown

    CVE-2014-1277

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3948. Reason: This candidate is a duplicate of CVE-2013-3948. Notes: All CVE users should reference CVE-2013-3948 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Mar 2014
    6.5
    Medium

    CVE-2014-0132

    Last Modified: 12 Apr 2025

    The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and gain privileges via the authzid parameter in a SASL/GSSAPI bind.

    Published: 13 Mar 2014
    10
    Critical

    CVE-2014-0510

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Adobe Flash Player 12.0.0.77 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism via unspecified vectors, as demonstrated by Zeguang Zhao and Liang Chen during a Pwn2Own competition at CanSecWest 2014.

    Published: 13 Mar 2014
    4.3
    Medium

    CVE-2014-2497

    Last Modified: 12 Apr 2025

    The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.

    Published: 13 Mar 2014
    3.5
    Low

    CVE-2013-3943

    Last Modified: 24 Apr 2026

    Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the Manage Profile.

    Published: 12 Mar 2014
    4.3
    Medium

    CVE-2013-1636

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitrary web script or HTML via the get-data parameter.

    Published: 12 Mar 2014
    4.3
    Medium

    CVE-2013-4649

    Last Modified: 24 Apr 2026

    Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.

    Published: 12 Mar 2014
    4.3
    Medium

    CVE-2013-7335

    Last Modified: 24 Apr 2026

    Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 12 Mar 2014
    7.5
    High

    CVE-2013-5117

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0299

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0305 and CVE-2014-0311.

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0306

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0321

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0313.

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0297

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0308, CVE-2014-0312, and CVE-2014-0324.

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0298

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0302

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0303.

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0303

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0302.

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0304

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0305

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0299 and CVE-2014-0311.

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0308

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0312, and CVE-2014-0324.

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0309

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0311

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0299 and CVE-2014-0305.

    Published: 12 Mar 2014