CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2013-6940

    Last Modified: 12 Apr 2025

    Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 logs user credentials, which allows attackers to obtain sensitive information via unspecified vectors.

    Published: 10 Mar 2014
    4.3
    Medium

    CVE-2013-6944

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the user interface in the AAA TM vServer in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Mar 2014
    5
    Medium

    CVE-2013-6939

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vectors, related to "RADIUS authentication."

    Published: 10 Mar 2014
    10
    Critical

    CVE-2013-6941

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows users to "breakout" of the shell via unknown vectors.

    Published: 10 Mar 2014
    6.8
    Medium

    CVE-2013-6942

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 10 Mar 2014
    7.5
    High

    CVE-2014-2318

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in ATCOM Netvolution 3 allows remote attackers to execute arbitrary SQL commands via the m parameter.

    Published: 10 Mar 2014
    5
    Medium

    CVE-2013-6943

    Last Modified: 12 Apr 2025

    Citrix NetScaler Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows remote attackers to conduct an LDAP injection attack via vectors related to SSH and Web management usernames.

    Published: 10 Mar 2014
    6.9
    Medium

    CVE-2014-0004

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.

    Published: 10 Mar 2014
    2.9
    Low

    CVE-2014-0131

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.

    Published: 10 Mar 2014
    5
    Medium

    CVE-2014-0128

    Last Modified: 12 Apr 2025

    Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.

    Published: 9 Mar 2014
    6.4
    Medium

    CVE-2013-4966

    Last Modified: 12 Apr 2025

    The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attackers to create arbitrary classifications on the master by spoofing a console.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2013-6233

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata."

    Published: 7 Mar 2014
    4.9
    Medium

    CVE-2013-7322

    Last Modified: 12 Apr 2025

    usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath.

    Published: 7 Mar 2014
    7.5
    High

    CVE-2014-1945

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the add_value parameter.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2014-2313

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2014-2314

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2014-2315

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Thank You Counter Button plugin 1.8.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) thanks_caption, (2) thanks_caption_style, or (3) thanks_style parameter to wp-admin/options.php.

    Published: 7 Mar 2014
    7.5
    High

    CVE-2014-2316

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the s parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 7 Mar 2014
    6.8
    Medium

    CVE-2014-2317

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these details are obtained from third party information.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2013-1890

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ownCloud Server before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) new_name parameter to apps/bookmarks/ajax/renameTag.php or (2) multiple unspecified parameters to unknown files in apps/contacts/ajax/.

    Published: 7 Mar 2014
    6.5
    Medium

    CVE-2013-1893

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in addressbookprovider.php in ownCloud Server before 5.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to the contacts application.

    Published: 7 Mar 2014
    6.5
    Medium

    CVE-2013-2045

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in lib/db.php in ownCloud Server 5.0.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Mar 2014
    6.5
    Medium

    CVE-2013-2046

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in lib/bookmarks.php in ownCloud Server 4.5.x before 4.5.11 and 5.x before 5.0.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2013-2270

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administration page in Airvana HubBub C1-600-RT and Sprint AIRAVE 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Mar 2014
    5
    Medium

    CVE-2013-4971

    Last Modified: 12 Apr 2025

    Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 7 Mar 2014
    3.5
    Low

    CVE-2013-6232

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2014-1599

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the SFR Box router with firmware NB6-MAIN-R3.3.4 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) dns, (2) dhcp, (3) nat, (4) route, or (5) lan in network/; or (6) wifi/config.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2014-1944

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the text parameter to index.php/guestbook/index/newentry.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2014-2281

    Last Modified: 12 Apr 2025

    The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 does not validate a certain length value, which allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted NFS packet.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2014-2282

    Last Modified: 12 Apr 2025

    The dissect_protocol_data_parameter function in epan/dissectors/packet-m3ua.c in the M3UA dissector in Wireshark 1.10.x before 1.10.6 does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) via a crafted SS7 MTP3 packet.

    Published: 7 Mar 2014
    4.3
    Medium

    CVE-2014-2283

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-rlc in the RLC dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 uses inconsistent memory-management approaches, which allows remote attackers to cause a denial of service (use-after-free error and application crash) via a crafted UMTS Radio Link Control packet.

    Published: 7 Mar 2014
    9.3
    Critical

    CVE-2014-2299

    Last Modified: 12 Apr 2025

    Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large record in MPEG data.

    Published: 7 Mar 2014
    5
    Medium

    CVE-2014-0098

    Last Modified: 12 Apr 2025

    The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation.

    Published: 7 Mar 2014
    7.5
    High

    CVE-2014-2240

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the cf2_hintmap_build function in cff/cf2hints.c in FreeType before 2.5.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of stem hints in a font file.

    Published: 7 Mar 2014
    4.7
    Medium

    CVE-2014-2673

    Last Modified: 12 Apr 2025

    The arch_dup_task_struct function in the Transactional Memory (TM) implementation in arch/powerpc/kernel/process.c in the Linux kernel before 3.13.7 on the powerpc platform does not properly interact with the clone and fork system calls, which allows local users to cause a denial of service (Program Check and system crash) via certain instructions that are executed with the processor in the Transactional state.

    Published: 7 Mar 2014
    6.8
    Medium

    CVE-2014-2241

    Last Modified: 12 Apr 2025

    The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to cause a denial of service (assertion failure), as demonstrated by a crafted ttf file.

    Published: 7 Mar 2014
    6.4
    Medium

    CVE-2014-1907

    Last Modified: 3 Nov 2025

    Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logout.php.

    Published: 6 Mar 2014
    4.3
    Medium

    CVE-2014-1906

    Last Modified: 3 Nov 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4) htmlchat.php, (5) video.php, or (6) videotext.php; (7) message parameter to lb_logout.php; or ct parameter to (8) lb_status.php or (9) v_status.php in ls/.

    Published: 6 Mar 2014
    1.9
    Low

    CVE-2011-3153

    Last Modified: 12 Apr 2025

    dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink attack on ~/.dmrc.

    Published: 6 Mar 2014
    4.3
    Medium

    CVE-2013-6315

    Last Modified: 12 Apr 2025

    IBM InfoSphere Enterprise Records 4.5.1 before 4.5.1.7-IER-IF001 and Enterprise Records 5.1.1 before 5.1.1.1-IER-IF003 do not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

    Published: 6 Mar 2014
    4
    Medium

    CVE-2014-0630

    Last Modified: 12 Apr 2025

    EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 allows remote authenticated users to read arbitrary files via a modified imaging-service URL.

    Published: 6 Mar 2014
    7.1
    High

    CVE-2014-0704

    Last Modified: 12 Apr 2025

    The IGMP implementation on Cisco Wireless LAN Controller (WLC) devices 4.x, 5.x, 6.x, 7.0 before 7.0.250.0, 7.1, 7.2, and 7.3, when IGMPv3 Snooping is enabled, allows remote attackers to cause a denial of service (memory over-read and device restart) via a crafted field in an IGMPv3 message, aka Bug ID CSCuh33240.

    Published: 6 Mar 2014
    7.8
    High

    CVE-2014-0706

    Last Modified: 12 Apr 2025

    Cisco Wireless LAN Controller (WLC) devices 7.2 before 7.2.115.2, 7.3, and 7.4 before 7.4.110.0 allow remote attackers to cause a denial of service (device restart) via a crafted 802.11 Ethernet frame, aka Bug ID CSCue87929.

    Published: 6 Mar 2014
    5
    Medium

    CVE-2013-3706

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the PreBoot service in Novell ZENworks Configuration Management (ZCM) 11.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a preboot update pathname, aka ZDI-CAN-1595.

    Published: 6 Mar 2014
    7.5
    High

    CVE-2013-6201

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in HP Security Management System 3.3.0, 3.5.0 before patch 1, and 3.6.0 before patch 2 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 6 Mar 2014
    4
    Medium

    CVE-2013-6304

    Last Modified: 12 Apr 2025

    Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.

    Published: 6 Mar 2014
    3.5
    Low

    CVE-2013-6314

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM InfoSphere Enterprise Records 4.5.1 before 4.5.1.7-IER-IF001 and Enterprise Records 5.1.1 before 5.1.1.1-IER-IF003 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Mar 2014
    6
    Medium

    CVE-2013-6719

    Last Modified: 12 Apr 2025

    delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the testconn_host parameter.

    Published: 6 Mar 2014
    4.3
    Medium

    CVE-2014-0335

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web client in Serena Dimensions CM 12.2 build 7.199.0 allow remote attackers to inject arbitrary web script or HTML via the (1) DB_CONN, (2) DB_NAME, (3) DM_HOST, (4) MAN_DB_NAME, (5) framecmd, (6) identifier, (7) merant.adm.adapters.AdmDialogPropertyMgr, (8) nav_frame, (9) nav_jsp, (10) target_frame, (11) id, or (12) type parameter to the dimensions/ URI.

    Published: 6 Mar 2014
    6.8
    Medium

    CVE-2014-0336

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web client in Serena Dimensions CM 12.2 build 7.199.0 allows remote attackers to hijack the authentication of administrators for requests that use the user_new_master parameter to the adminconsole/ URI.

    Published: 6 Mar 2014