CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2014-0312

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0308, and CVE-2014-0324.

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0313

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0321.

    Published: 12 Mar 2014
    5.4
    Medium

    CVE-2014-0317

    Last Modified: 12 Apr 2025

    The Security Account Manager Remote (SAMR) protocol implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 Gold and R2 does not properly determine the user-lockout state, which makes it easier for remote attackers to bypass the account lockout policy and obtain access via a brute-force attack, aka "SAMR Security Feature Bypass Vulnerability."

    Published: 12 Mar 2014
    7.1
    High

    CVE-2014-0319

    Last Modified: 12 Apr 2025

    Microsoft Silverlight 5 before 5.1.30214.0 and Silverlight 5 Developer Runtime before 5.1.30214.0 allow attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors, aka "Silverlight DEP/ASLR Bypass Vulnerability."

    Published: 12 Mar 2014
    6.6
    Medium

    CVE-2014-0323

    Last Modified: 12 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (system hang) via a crafted application, aka "Win32k Information Disclosure Vulnerability."

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0324

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0297, CVE-2014-0308, and CVE-2014-0312.

    Published: 12 Mar 2014
    7.2
    High

    CVE-2014-0300

    Last Modified: 12 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0301

    Last Modified: 12 Apr 2025

    Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via a crafted JPEG image, aka "DirectShow Memory Corruption Vulnerability."

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0307

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a certain sequence of manipulations of a TextRange element, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Mar 2014
    9.3
    Critical

    CVE-2014-0314

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Mar 2014
    5
    Medium

    CVE-2013-4496

    Last Modified: 12 Apr 2025

    Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obtain access via brute-force ChangePasswordUser2 (1) SAMR or (2) RAP attempts.

    Published: 12 Mar 2014
    5.8
    Medium

    CVE-2013-6442

    Last Modified: 12 Apr 2025

    The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

    Published: 12 Mar 2014
    7.5
    High

    CVE-2014-1721

    Last Modified: 12 Apr 2025

    Google V8, as used in Google Chrome before 34.0.1847.116, does not properly implement lazy deoptimization, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code, as demonstrated by improper handling of a heap allocation of a number outside the Small Integer (aka smi) range.

    Published: 12 Mar 2014
    6.8
    Medium

    CVE-2013-7334

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in ImageCMS before 4.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the q parameter, related to CVE-2012-6290.

    Published: 11 Mar 2014
    9.3
    Critical

    CVE-2013-3928

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.

    Published: 11 Mar 2014
    6.5
    Medium

    CVE-2013-3961

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to execute arbitrary SQL commands via the eventid parameter.

    Published: 11 Mar 2014
    4.3
    Medium

    CVE-2013-4188

    Last Modified: 12 Apr 2025

    traverser.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers with administrator privileges to cause a denial of service (infinite loop and resource consumption) via unspecified vectors related to "retrieving information for certain resources."

    Published: 11 Mar 2014
    6.5
    Medium

    CVE-2013-4189

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users with administrator access to a subtree to access nodes above the subtree via unknown vectors.

    Published: 11 Mar 2014
    5.8
    Medium

    CVE-2013-4191

    Last Modified: 12 Apr 2025

    zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in a zip archive, which allows remote attackers to obtain sensitive information by reading a generated archive.

    Published: 11 Mar 2014
    4
    Medium

    CVE-2013-4192

    Last Modified: 12 Apr 2025

    sendto.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to spoof emails via unspecified vectors.

    Published: 11 Mar 2014
    4.3
    Medium

    CVE-2013-4194

    Last Modified: 12 Apr 2025

    The WYSIWYG component (wysiwyg.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers to obtain sensitive information via a crafted URL, which reveals the installation path in an error message.

    Published: 11 Mar 2014
    5.8
    Medium

    CVE-2013-4195

    Last Modified: 12 Apr 2025

    Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 11 Mar 2014
    5
    Medium

    CVE-2013-4196

    Last Modified: 12 Apr 2025

    The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restrict access to internal methods, which allows remote attackers to obtain sensitive information via a crafted request.

    Published: 11 Mar 2014
    5.5
    Medium

    CVE-2013-4197

    Last Modified: 12 Apr 2025

    member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.

    Published: 11 Mar 2014
    4
    Medium

    CVE-2013-4198

    Last Modified: 12 Apr 2025

    mail_password.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to bypass the prohibition on password changes via the forgotten password email functionality.

    Published: 11 Mar 2014
    3.5
    Low

    CVE-2013-4199

    Last Modified: 12 Apr 2025

    (1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompressed).

    Published: 11 Mar 2014
    5
    Medium

    CVE-2013-4413

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.

    Published: 11 Mar 2014
    6.5
    Medium

    CVE-2013-4467

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQL commands via the campaign variable in SCRIPT_multirecording_AJAX.php, (2) remote authenticated users to execute arbitrary SQL commands via the server_ip parameter to manager_send.php, or (3) other unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 11 Mar 2014
    7.5
    High

    CVE-2014-2311

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in modx.class.php in MODX Revolution 2.0.0 before 2.2.13 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 11 Mar 2014
    4.3
    Medium

    CVE-2013-2289

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/templates/default.php in Batavi 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to admin/index.php.

    Published: 11 Mar 2014
    7.5
    High

    CVE-2013-5639

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the gnew_language cookie.

    Published: 11 Mar 2014
    4.4
    Medium

    CVE-2014-1839

    Last Modified: 12 Apr 2025

    The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file.

    Published: 11 Mar 2014
    6.8
    Medium

    CVE-2013-2754

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a request to admin/users/add/user/do/.

    Published: 11 Mar 2014
    4.3
    Medium

    CVE-2013-4190

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) pts.py, and (3) request.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Mar 2014
    4.3
    Medium

    CVE-2013-4193

    Last Modified: 12 Apr 2025

    typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.

    Published: 11 Mar 2014
    4.3
    Medium

    CVE-2013-4433

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in XHProf before 0.9.4 allows remote attackers to inject arbitrary web script or HTML via the run parameter.

    Published: 11 Mar 2014
    4.4
    Medium

    CVE-2014-1838

    Last Modified: 12 Apr 2025

    The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-commons before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.

    Published: 11 Mar 2014
    6.5
    Medium

    CVE-2012-6290

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL commands via the q parameter to admin/admin_search/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

    Published: 11 Mar 2014
    10
    Critical

    CVE-2014-2321

    Last Modified: 12 Apr 2025

    web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by using "set TelnetCfg" commands to enable a TELNET service with specified credentials.

    Published: 11 Mar 2014
    6.5
    Medium

    CVE-2014-0899

    Last Modified: 12 Apr 2025

    ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.

    Published: 11 Mar 2014
    4.3
    Medium

    CVE-2013-6031

    Last Modified: 12 Apr 2025

    The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remote attackers to change passwords and settings, or obtain sensitive information, via a direct request to (1) api/wlan/security-settings, (2) api/device/information, (3) api/wlan/basic-settings, (4) api/wlan/mac-filter, (5) api/monitoring/status, or (6) api/dhcp/settings.

    Published: 11 Mar 2014
    6.2
    Medium

    CVE-2013-6200

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in m4 in HP HP-UX B.11.23 and B.11.31 allows local users to obtain sensitive information or modify data via unknown vectors.

    Published: 11 Mar 2014
    9.4
    Critical

    CVE-2013-6207

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the loadFileContents function in the SOAP implementation in HP SiteScope 10.1x, 11.1x, and 11.21 allows remote attackers to read arbitrary files or cause a denial of service via unknown vectors, aka ZDI-CAN-2084.

    Published: 11 Mar 2014
    4.3
    Medium

    CVE-2013-6037

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in Aker Secure Mail Gateway 2.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg_id parameter.

    Published: 11 Mar 2014
    6.8
    Medium

    CVE-2013-6475

    Last Modified: 12 Apr 2025

    Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.

    Published: 11 Mar 2014
    6.1
    Medium

    CVE-2013-0186

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Mar 2014
    7.5
    High

    CVE-2014-0057

    Last Modified: 12 Apr 2025

    The x_button method in the ServiceController (vmdb/app/controllers/service_controller.rb) in Red Hat CloudForms 3.0 Management Engine 5.2 allows remote attackers to execute arbitrary methods via unspecified vectors.

    Published: 11 Mar 2014
    5
    Medium

    CVE-2014-0504

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows attackers to read the clipboard via unspecified vectors.

    Published: 11 Mar 2014
    6.4
    Medium

    CVE-2014-0503

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 11.7.700.272 and 11.8.x through 12.0.x before 12.0.0.77 on Windows and OS X, and before 11.2.202.346 on Linux, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 11 Mar 2014
    5
    Medium

    CVE-2013-6938

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Service VM in Citrix NetScaler SDX 9.3 before 9.3-64.4 and 10.0 before 10.0-77.5 and Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vectors, related to the "Virtual Machine Daemon."

    Published: 10 Mar 2014