CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2014-0279

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0277 and CVE-2014-0278.

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0280

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0281

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0287.

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0284

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0285

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0275 and CVE-2014-0286.

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0286

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0275 and CVE-2014-0285.

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0287

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0281.

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0288

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0273, and CVE-2014-0274.

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0289

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0267 and CVE-2014-0290.

    Published: 12 Feb 2014
    10
    Critical

    CVE-2014-0294

    Last Modified: 11 Apr 2025

    Microsoft Forefront Protection 2010 for Exchange Server does not properly parse e-mail content, which might allow remote attackers to execute arbitrary code via a crafted message, aka "RCE Vulnerability."

    Published: 12 Feb 2014
    10
    Critical

    CVE-2014-0500

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0501.

    Published: 12 Feb 2014
    10
    Critical

    CVE-2014-0501

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0500.

    Published: 12 Feb 2014
    5
    Medium

    CVE-2014-0253

    Last Modified: 11 Apr 2025

    Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attackers to cause a denial of service (ASP.NET daemon hang) via crafted HTTP requests that trigger persistent resource consumption for a (1) stale or (2) closed connection, as exploited in the wild in February 2014, aka "POST Request DoS Vulnerability."

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0274

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0270, CVE-2014-0273, and CVE-2014-0288.

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0277

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0278 and CVE-2014-0279.

    Published: 12 Feb 2014
    9.3
    Critical

    CVE-2014-0283

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Feb 2014
    4.3
    Medium

    CVE-2014-0293

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."

    Published: 12 Feb 2014
    4.3
    Medium

    CVE-2014-0295

    Last Modified: 11 Apr 2025

    VsaVb7rt.dll in Microsoft .NET Framework 2.0 SP2 and 3.5.1 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in February 2014, aka "VSAVB7RT ASLR Vulnerability."

    Published: 12 Feb 2014
    5
    Medium

    CVE-2013-6401

    Last Modified: 12 Apr 2025

    Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted JSON document.

    Published: 12 Feb 2014
    2.6
    Low

    CVE-2014-1948

    Last Modified: 11 Apr 2025

    OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.

    Published: 12 Feb 2014
    4.6
    Medium

    CVE-2014-1950

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the xc_cpupool_getinfo function in Xen 4.1.x through 4.3.x, when using a multithreaded toolstack, does not properly handle a failure by the xc_cpumap_alloc function, which allows local users with access to management functions to cause a denial of service (heap corruption) and possibly gain privileges via unspecified vectors.

    Published: 12 Feb 2014
    5.8
    Medium

    CVE-2014-1959

    Last Modified: 12 Apr 2025

    lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates.

    Published: 12 Feb 2014
    7.5
    High

    CVE-2014-2063

    Last Modified: 12 Apr 2025

    Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 12 Feb 2014
    6.8
    Medium

    CVE-2014-2066

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.

    Published: 12 Feb 2014
    5.5
    Medium

    CVE-2014-0083

    Last Modified: 21 Nov 2024

    The Ruby net-ldap gem before 0.11 uses a weak salt when generating SSHA passwords.

    Published: 12 Feb 2014
    7.5
    High

    CVE-2014-2015

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.

    Published: 12 Feb 2014
    4.3
    Medium

    CVE-2013-3933

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the JoomShopping (com_joomshopping) component before 4.3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the user_name parameter to index.php.

    Published: 11 Feb 2014
    4.3
    Medium

    CVE-2013-1413

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in synetics i-doit open 0.9.9-7, i-doit pro 1.0 and earlier, and i-doit pro 1.0.2 when the 'sanitize user input' flag is not enabled, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Feb 2014
    4.3
    Medium

    CVE-2013-2639

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the description in a project folder.

    Published: 11 Feb 2014
    7.5
    High

    CVE-2013-3294

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execute arbitrary SQL commands via the (1) src or (2) username parameter to index.php.

    Published: 11 Feb 2014
    9.3
    Critical

    CVE-2014-0980

    Last Modified: 11 Apr 2025

    Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI file.

    Published: 11 Feb 2014
    4.3
    Medium

    CVE-2014-1237

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in synetics i-doit pro before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via the call parameter.

    Published: 11 Feb 2014
    6.5
    Medium

    CVE-2014-1401

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in AuraCMS 2.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) search parameter to mod/content/content.php or (2) CLIENT_IP, (3) X_FORWARDED_FOR, (4) X_FORWARDED, (5) FORWARDED_FOR, or (6) FORWARDED HTTP header to index.php.

    Published: 11 Feb 2014
    6.5
    Medium

    CVE-2014-1459

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the _position_down_id parameter. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

    Published: 11 Feb 2014
    6.8
    Medium

    CVE-2013-1980

    Last Modified: 11 Apr 2025

    Buffer overflow in the get_dsmp function in loaders/masi_load.c in libxmp before 4.1.0 allows remote attackers to execute arbitrary code via a crafted MASI file.

    Published: 11 Feb 2014
    6.5
    Medium

    CVE-2013-5012

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 11 Feb 2014
    4.3
    Medium

    CVE-2013-5013

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote attackers to inject arbitrary web script or HTML via (1) vectors involving PHP scripts and (2) unspecified other vectors.

    Published: 11 Feb 2014
    5
    Medium

    CVE-2014-1878

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to cause a denial of service (segmentation fault) via a long message to cmd.cgi.

    Published: 11 Feb 2014
    5
    Medium

    CVE-2014-2060

    Last Modified: 12 Apr 2025

    The Winstone servlet container in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack sessions via unspecified vectors.

    Published: 11 Feb 2014
    4
    Medium

    CVE-2013-7330

    Last Modified: 12 Apr 2025

    Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related to post-build actions.

    Published: 11 Feb 2014
    5.5
    Medium

    CVE-2014-0068

    Last Modified: 21 Nov 2024

    It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.

    Published: 11 Feb 2014
    Unknown

    CVE-2012-5546

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This identifier was publicly assigned by its CNA to information that was incorrectly specified due to a typo. Notes: none

    Published: 10 Feb 2014
    5
    Medium

    CVE-2013-2055

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and reading the information that is outside of wicket:panel markup.

    Published: 10 Feb 2014
    5.6
    Medium

    CVE-2014-1213

    Last Modified: 11 Apr 2025

    Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.x before 10.3.1 does not set an ACL for certain global and session objects, which allows local users to bypass anti-virus protection, cause a denial of service (resource consumption, CPU consumption, and eventual crash) or spoof "ready for update" messages by performing certain operations on mutexes or events including (1) DataUpdateRequest, (2) MmfMutexSAV-****, (3) MmfMutexSAV-Info, (4) ReadyForUpdateSAV-****, (5) ReadyForUpdateSAV-Info, (6) SAV-****, (7) SAV-Info, (8) StateChange, (9) SuspendedSAV-****, (10) SuspendedSAV-Info, (11) UpdateComplete, (12) UpdateMutex, (13) UpdateRequest, or (14) SophosALMonSessionInstance, as demonstrated by triggering a ReadyForUpdateSAV event and modifying the UpdateComplete, UpdateMutex, and UpdateRequest objects.

    Published: 10 Feb 2014
    4.3
    Medium

    CVE-2014-1931

    Last Modified: 11 Apr 2025

    The user login page in Visibility Software Cyber Recruiter before 8.1.00 generates different responses for invalid password-retrieval attempts depending on which data elements are incorrect, which might allow remote attackers to obtain account-related information via a series of requests.

    Published: 10 Feb 2014
    4.3
    Medium

    CVE-2014-1930

    Last Modified: 11 Apr 2025

    Visibility Software Cyber Recruiter before 8.1.00 does not use the appropriate combination of HTTPS transport and response headers to prevent access to (1) AppSelfService.aspx and (2) AgencyPortal.aspx in the browser history, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

    Published: 10 Feb 2014
    5.8
    Medium

    CVE-2011-4092

    Last Modified: 11 Apr 2025

    obby (aka libobby) does not verify SSL server certificates, which allows remote attackers to spoof servers via an arbitrary certificate.

    Published: 10 Feb 2014
    4.4
    Medium

    CVE-2013-6024

    Last Modified: 11 Apr 2025

    The Edge Client components in F5 BIG-IP APM 10.x, 11.x, 12.x, 13.x, and 14.x, BIG-IP Edge Gateway 10.x and 11.x, and FirePass 7.0.0 allow attackers to obtain sensitive information from process memory via unspecified vectors.

    Published: 10 Feb 2014
    Unknown

    CVE-2010-3090

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-3089. Reason: This issue was MERGED into CVE-2010-3089 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2010-3089 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Feb 2014
    7.8
    High

    CVE-2013-4736

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the JPEG engine drivers in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service (system crash) via a large number of commands in an ioctl call, related to (1) camera_v1/gemini/msm_gemini_sync.c, (2) camera_v2/gemini/msm_gemini_sync.c, (3) camera_v2/jpeg_10/msm_jpeg_sync.c, (4) gemini/msm_gemini_sync.c, (5) jpeg_10/msm_jpeg_sync.c, and (6) mercury/msm_mercury_sync.c.

    Published: 10 Feb 2014