CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2011-4091

    Last Modified: 11 Apr 2025

    The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user and color preferences.

    Published: 10 Feb 2014
    5.8
    Medium

    CVE-2011-4093

    Last Modified: 11 Apr 2025

    Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user is provided.

    Published: 10 Feb 2014
    3.5
    Low

    CVE-2012-6149

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in systems/sdc/notes.jsp in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) subject or (2) content values of a note in a system.addNote XML-RPC call.

    Published: 10 Feb 2014
    4.3
    Medium

    CVE-2013-1869

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks, via the return_url parameter.

    Published: 10 Feb 2014
    3.5
    Low

    CVE-2013-1871

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in account/EditAddress.do in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allows remote attackers to inject arbitrary web script or HTML via the type parameter.

    Published: 10 Feb 2014
    6
    Medium

    CVE-2010-2236

    Last Modified: 12 Apr 2025

    The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.

    Published: 10 Feb 2014
    4.3
    Medium

    CVE-2013-4415

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) whereCriteria variable in a software channels search; (2) end_year, (3) start_hour, (4) end_am_pm, (5) end_day, (6) end_hour, (7) end_minute, (8) end_month, (9) end_year, (10) optionScanDateSearch, (11) result_filter, (12) search_string, (13) show_as, (14) start_am_pm, (15) start_day, (16) start_hour, (17) start_minute, (18) start_month, (19) start_year, or (20) whereToSearch variable in an scap audit results search; (21) end_minute, (22) end_month, (23) end_year, (24) errata_type_bug, (25) errata_type_enhancement, (26) errata_type_security, (27) fineGrained, (28) list_1892635924_sortdir, (29) optionIssueDateSearch, (30) start_am_pm, (31) start_day, (32) start_hour, (33) start_minute, (34) start_month, (35) start_year, or (36) view_mode variable in an errata search; or (37) fineGrained variable in a systems search, related to PAGE_SIZE_LABEL_SELECTED.

    Published: 10 Feb 2014
    5
    Medium

    CVE-2014-1943

    Last Modified: 11 Apr 2025

    Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.

    Published: 10 Feb 2014
    10
    Critical

    CVE-2015-0278

    Last Modified: 12 Apr 2025

    libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.

    Published: 10 Feb 2014
    4.7
    Medium

    CVE-2015-3248

    Last Modified: 20 Apr 2025

    openhpi/Makefile.am in OpenHPI before 3.6.0 uses world-writable permissions for /var/lib/openhpi directory, which allows local users, when quotas are not properly setup, to fill the filesystem hosting /var/lib and cause a denial of service (disk consumption).

    Published: 10 Feb 2014
    8.6
    High

    CVE-2012-5562

    Last Modified: 9 Apr 2026

    A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.

    Published: 10 Feb 2014
    5
    Medium

    CVE-2014-1868

    Last Modified: 12 Apr 2025

    Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expansion (XEE) attack.

    Published: 9 Feb 2014
    7.5
    High

    CVE-2014-0045

    Last Modified: 11 Apr 2025

    The needSamples method in AudioOutputSpeech.cpp in the client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots, Mumble for iOS 1.1 through 1.2.2, and MumbleKit before commit fd190328a9b24d37382b269a5674b0c0c7a7e36d does not check the return value of the opus_decode_float function, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Opus voice packet, which triggers an error in opus_decode_float, a conversion of a negative integer to an unsigned integer, and a heap-based buffer over-read and over-write.

    Published: 8 Feb 2014
    4.3
    Medium

    CVE-2012-5524

    Last Modified: 11 Apr 2025

    The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) attacks and spoof servers via an arbitrary certificate from a trusted CA.

    Published: 8 Feb 2014
    5
    Medium

    CVE-2013-1904

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in steps/mail/sendmail.inc in Roundcube Webmail before 0.7.3 and 0.8.x before 0.8.6 allows remote attackers to read arbitrary files via a full pathname in the _value parameter for the generic_message_footer setting in a save-perf action to index.php, as exploited in the wild in March 2013.

    Published: 8 Feb 2014
    4.3
    Medium

    CVE-2013-2191

    Last Modified: 11 Apr 2025

    python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.

    Published: 8 Feb 2014
    4.4
    Medium

    CVE-2014-0039

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in fwsnort before 1.6.4, when not running as root, allows local users to execute arbitrary code via a Trojan horse fwsnort.conf in the current working directory.

    Published: 8 Feb 2014
    5
    Medium

    CVE-2014-0044

    Last Modified: 11 Apr 2025

    The opus_packet_get_samples_per_frame function in client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots allows remote attackers to cause a denial of service (crash) via a crafted length prefix value, which triggers a NULL pointer dereference or a heap-based buffer over-read (aka "out-of-bounds array access").

    Published: 8 Feb 2014
    5
    Medium

    CVE-2014-1916

    Last Modified: 11 Apr 2025

    The (1) opus_packet_get_nb_frames and (2) opus_packet_get_samples_per_frame functions in the client in MumbleKit before commit fd190328a9b24d37382b269a5674b0c0c7a7e36d and Mumble for iOS 1.1 through 1.2.2 do not properly check the return value of the copyDataBlock method, which allow remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted length prefix value in an Opus voice packet.

    Published: 8 Feb 2014
    6.8
    Medium

    CVE-2014-1915

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to hijack the authentication of (1) administrators for requests that change the administrator password via an update action to sw/admin_change_password.php or (2) unspecified victims for requests that add a topic or blog entry to sw/add_topic.php. NOTE: vector 2 can be leveraged to bypass the authentication requirements for exploiting vector 1 in CVE-2014-1914.

    Published: 7 Feb 2014
    4.3
    Medium

    CVE-2014-1914

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to inject arbitrary web script or HTML via the (1) topic parameter to sw/add_topic.php or (2) nick parameter to sw/chat/message.php.

    Published: 7 Feb 2014
    4
    Medium

    CVE-2014-1643

    Last Modified: 11 Apr 2025

    The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allows remote authenticated users to read the stored outbound e-mail messages of arbitrary users via a modified URL.

    Published: 7 Feb 2014
    5
    Medium

    CVE-2014-1696

    Last Modified: 11 Apr 2025

    Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 7 Feb 2014
    7.5
    High

    CVE-2014-1697

    Last Modified: 11 Apr 2025

    The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitrary code via crafted packets to TCP port 4999.

    Published: 7 Feb 2014
    5
    Medium

    CVE-2014-1698

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read arbitrary files via crafted packets to TCP port 4999.

    Published: 7 Feb 2014
    5
    Medium

    CVE-2014-1699

    Last Modified: 11 Apr 2025

    Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-service outage) via malformed HTTP requests to port 4999.

    Published: 7 Feb 2014
    6.5
    Medium

    CVE-2014-2059

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the CLI job creation (hudson/cli/CreateJobCommand.java) in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to overwrite arbitrary files via the job name.

    Published: 7 Feb 2014
    3.5
    Low

    CVE-2014-2067

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in java/hudson/model/Cause.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to inject arbitrary web script or HTML via a "remote cause note."

    Published: 7 Feb 2014
    6.5
    Medium

    CVE-2014-2062

    Last Modified: 12 Apr 2025

    Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.

    Published: 7 Feb 2014
    5
    Medium

    CVE-2014-2064

    Last Modified: 12 Apr 2025

    The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.

    Published: 7 Feb 2014
    4.3
    Medium

    CVE-2014-2065

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to inject arbitrary web script or HTML via the iconSize cookie.

    Published: 7 Feb 2014
    4.3
    Medium

    CVE-2013-5855

    Last Modified: 12 Apr 2025

    Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.

    Published: 7 Feb 2014
    5
    Medium

    CVE-2014-2061

    Last Modified: 12 Apr 2025

    The input control in PasswordParameterDefinition in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to obtain passwords by reading the HTML source code, related to the default value.

    Published: 7 Feb 2014
    3.5
    Low

    CVE-2014-2068

    Last Modified: 12 Apr 2025

    The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users with the ADMINISTER permission to obtain sensitive information via vectors related to heapDump.

    Published: 7 Feb 2014
    4.9
    Medium

    CVE-2013-2962

    Last Modified: 11 Apr 2025

    Buffer overflow in the Launcher in IBM WebSphere Transformation Extender 8.4.x before 8.4.0.4 allows local users to cause a denial of service (process crash or Admin Console command-stream outage) via unspecified vectors.

    Published: 6 Feb 2014
    8.5
    High

    CVE-2013-6332

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in IBM Algo One UDS 4.7.0 through 5.0.0 allows remote authenticated users to execute arbitrary code by uploading a .jsp file and then launching it.

    Published: 6 Feb 2014
    4.3
    Medium

    CVE-2014-0330

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in adminui/user_list.php on the Dell KACE K1000 management appliance 5.5.90545 allows remote attackers to inject arbitrary web script or HTML via the LABEL_ID parameter.

    Published: 6 Feb 2014
    7.8
    High

    CVE-2014-0822

    Last Modified: 11 Apr 2025

    The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, aka SPR KLYH9F4S2Z.

    Published: 6 Feb 2014
    4.3
    Medium

    CVE-2014-1870

    Last Modified: 11 Apr 2025

    Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-and-drop operation.

    Published: 6 Feb 2014
    9
    Critical

    CVE-2014-0622

    Last Modified: 11 Apr 2025

    The web service in EMC Documentum Foundation Services (DFS) 6.5 through 6.7 before 6.7 SP1 P22, 6.7 SP2 before P08, 7.0 before P12, and 7.1 before P01 does not properly implement content uploading, which allows remote authenticated users to bypass intended content access restrictions via unspecified vectors.

    Published: 6 Feb 2014
    4.3
    Medium

    CVE-2014-0815

    Last Modified: 11 Apr 2025

    The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by reading stored cookies.

    Published: 6 Feb 2014
    4.3
    Medium

    CVE-2012-1095

    Last Modified: 11 Apr 2025

    osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.

    Published: 6 Feb 2014
    4.3
    Medium

    CVE-2013-2038

    Last Modified: 11 Apr 2025

    The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpreted sentence that lacks certain fields and a terminator. NOTE: a separate issue in the AIS driver was also reported, but it might not be a vulnerability.

    Published: 6 Feb 2014
    5
    Medium

    CVE-2014-1663

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix XenMobile Device Manager server (formerly Zenprise Device Manager server) 8.5, 8.6, and MDM 8.0.1 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 6 Feb 2014
    7.2
    High

    CVE-2010-4226

    Last Modified: 9 Jun 2025

    cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.

    Published: 6 Feb 2014
    9.3
    Critical

    CVE-2013-6486

    Last Modified: 11 Apr 2025

    gtkutils.c in Pidgin before 2.10.8 on Windows allows user-assisted remote attackers to execute arbitrary programs via a message containing a file: URL that is improperly handled during construction of an explorer.exe command. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3185.

    Published: 6 Feb 2014
    6.8
    Medium

    CVE-2013-7320

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in D-Link DAP-2253 Access Point (Rev. A1) with firmware before 1.30 allows remote attackers to hijack the authentication of administrators for requests that modify configuration settings via unspecified vectors.

    Published: 6 Feb 2014
    4.3
    Medium

    CVE-2013-5983

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) "an" parameter to agenda.php or (2) cat parameter to mobile/thread.php.

    Published: 6 Feb 2014
    4.3
    Medium

    CVE-2013-7321

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in D-Link DAP-2253 Access Point (Rev. A1) with firmware before 1.30 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Feb 2014
    4.3
    Medium

    CVE-2013-7319

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.

    Published: 6 Feb 2014