CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2014-0834

    Last Modified: 11 Apr 2025

    IBM General Parallel File System (GPFS) 3.4 through 3.4.0.27 and 3.5 through 3.5.0.16 allows attackers to cause a denial of service (daemon crash) via crafted arguments to a setuid program.

    Published: 4 Feb 2014
    4.3
    Medium

    CVE-2014-1491

    Last Modified: 25 Nov 2025

    Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.

    Published: 4 Feb 2014
    9.3
    Critical

    CVE-2014-1490

    Last Modified: 25 Nov 2025

    Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.

    Published: 4 Feb 2014
    7.5
    High

    CVE-2014-1487

    Last Modified: 25 Nov 2025

    The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.

    Published: 4 Feb 2014
    9.8
    Critical

    CVE-2014-1486

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data.

    Published: 4 Feb 2014
    7.5
    High

    CVE-2014-1479

    Last Modified: 25 Nov 2025

    The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content scopes.

    Published: 4 Feb 2014
    9.8
    Critical

    CVE-2014-1477

    Last Modified: 25 Nov 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 4 Feb 2014
    9.8
    Critical

    CVE-2014-0497

    Last Modified: 21 Apr 2026

    Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 4 Feb 2014
    10
    Critical

    CVE-2014-1478

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the MPostWriteBarrier class in js/src/jit/MIR.h and stack alignment in js/src/jit/AsmJS.cpp in OdinMonkey, and unknown other vectors.

    Published: 4 Feb 2014
    8.8
    High

    CVE-2014-1482

    Last Modified: 25 Nov 2025

    RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.

    Published: 4 Feb 2014
    7.5
    High

    CVE-2014-1485

    Last Modified: 11 Apr 2025

    The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.

    Published: 4 Feb 2014
    4.3
    Medium

    CVE-2014-1489

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.

    Published: 4 Feb 2014
    4.3
    Medium

    CVE-2014-1480

    Last Modified: 11 Apr 2025

    The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.

    Published: 4 Feb 2014
    10
    Critical

    CVE-2014-1488

    Last Modified: 11 Apr 2025

    The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.

    Published: 4 Feb 2014
    5
    Medium

    CVE-2014-1483

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.

    Published: 4 Feb 2014
    7.5
    High

    CVE-2014-1481

    Last Modified: 25 Nov 2025

    Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.

    Published: 4 Feb 2014
    5
    Medium

    CVE-2012-2249

    Last Modified: 11 Apr 2025

    Tor before 0.2.3.23-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a renegotiation attempt that occurs after the initiation of the V3 link protocol.

    Published: 3 Feb 2014
    5
    Medium

    CVE-2012-2250

    Last Modified: 11 Apr 2025

    Tor before 0.2.3.24-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) by performing link protocol negotiation incorrectly.

    Published: 3 Feb 2014
    7.2
    High

    CVE-2013-4738

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to gain privileges via (1) a crafted VIDIOC_MSM_VPE_DEQUEUE_STREAM_BUFF_INFO ioctl call, related to drivers/media/platform/msm/camera_v2/pproc/vpe/msm_vpe.c, or (2) a crafted VIDIOC_MSM_CPP_DEQUEUE_STREAM_BUFF_INFO ioctl call, related to drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c.

    Published: 3 Feb 2014
    4.9
    Medium

    CVE-2013-4739

    Last Modified: 11 Apr 2025

    The MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to obtain sensitive information from kernel stack memory via (1) a crafted MSM_MCR_IOCTL_EVT_GET ioctl call, related to drivers/media/platform/msm/camera_v1/mercury/msm_mercury_sync.c, or (2) a crafted MSM_JPEG_IOCTL_EVT_GET ioctl call, related to drivers/media/platform/msm/camera_v2/jpeg_10/msm_jpeg_sync.c.

    Published: 3 Feb 2014
    4.4
    Medium

    CVE-2014-1876

    Last Modified: 11 Apr 2025

    The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.

    Published: 3 Feb 2014
    4.9
    Medium

    CVE-2014-2039

    Last Modified: 12 Apr 2025

    arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use of the linkage stack, which allows local users to cause a denial of service (system crash) by executing a crafted instruction.

    Published: 3 Feb 2014
    5.9
    Medium

    CVE-2014-8167

    Last Modified: 21 Nov 2024

    vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

    Published: 3 Feb 2014
    4.3
    Medium

    CVE-2013-0234

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_username] parameter to action/widgets/save.

    Published: 2 Feb 2014
    2.1
    Low

    CVE-2013-4331

    Last Modified: 11 Apr 2025

    Light Display Manager (aka LightDM) 1.4.x before 1.4.3, 1.6.x before 1.6.2, and 1.7.x before 1.7.14 uses 0664 permissions for the temporary .Xauthority file, which allows local users to obtain sensitive information by reading the file.

    Published: 2 Feb 2014
    5
    Medium

    CVE-2013-7300

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in cantata before 1.2.2 allows local users to read arbitrary files via a full pathname in a request to the internal httpd server. NOTE: this vulnerability can be leveraged by remote attackers using CVE-2013-7301.

    Published: 2 Feb 2014
    5
    Medium

    CVE-2013-7301

    Last Modified: 11 Apr 2025

    Cantata before 1.2.2 does not restrict access to files in the play queue, which allows remote attackers to obtain sensitive information by reading the songs in the queue.

    Published: 2 Feb 2014
    5
    Medium

    CVE-2013-4043

    Last Modified: 11 Apr 2025

    The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attackers to read arbitrary files via an unspecified HTTP request.

    Published: 1 Feb 2014
    5
    Medium

    CVE-2013-7177

    Last Modified: 11 Apr 2025

    config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail address that matches an improperly designed regular expression.

    Published: 1 Feb 2014
    5.5
    Medium

    CVE-2014-0833

    Last Modified: 11 Apr 2025

    The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which allows remote authenticated users to bypass intended access restrictions via an unspecified process step.

    Published: 1 Feb 2014
    9.3
    Critical

    CVE-2013-6724

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the vsflex8l ActiveX control in IBM SPSS SamplePower 3.0.1 before FP1 IF1 allows remote attackers to execute arbitrary code via a crafted ComboList property value.

    Published: 1 Feb 2014
    5
    Medium

    CVE-2013-7176

    Last Modified: 11 Apr 2025

    config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail address that matches an improperly designed regular expression.

    Published: 1 Feb 2014
    4.3
    Medium

    CVE-2014-0812

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in KENT-WEB Joyful Note 2.8 and earlier, when Internet Explorer 7 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Feb 2014
    4
    Medium

    CVE-2014-0830

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the table-export implementation in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 and 2.1 before 2.1.0.1 allows remote authenticated users to read arbitrary files via a modified pathname.

    Published: 1 Feb 2014
    6.8
    Medium

    CVE-2014-0831

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allows remote attackers to hijack the authentication of arbitrary users for requests that modify configuration data.

    Published: 1 Feb 2014
    3.5
    Low

    CVE-2014-0832

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in configuration-details screens in the OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 allow remote authenticated users to inject arbitrary web script or HTML via a crafted text value.

    Published: 1 Feb 2014
    5
    Medium

    CVE-2013-6143

    Last Modified: 11 Apr 2025

    The Schneider Electric Telvent SAGE 3030 RTU with firmware C3413-500-001D3_P4 and C3413-500-001F0_PB allows remote attackers to cause a denial of service (temporary outage and CPU consumption) via malformed DNP3 traffic.

    Published: 31 Jan 2014
    7.5
    High

    CVE-2014-1204

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Tableau Server 8.0.x before 8.0.7 and 8.1.x before 8.1.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. NOTE: this can be exploited by unauthenticated remote attackers if the guest user is enabled.

    Published: 31 Jan 2014
    9.3
    Critical

    CVE-2013-4979

    Last Modified: 11 Apr 2025

    Buffer overflow in the gldll32.dll module in EPS Viewer 3.2 and earlier allows remote attackers to execute arbitrary code via a crafted EPS file.

    Published: 31 Jan 2014
    2.1
    Low

    CVE-2013-4383

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the jQuery Countdown module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "access administration pages" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Jan 2014
    4.3
    Medium

    CVE-2013-6235

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in JAMon (Java Application Monitor) 2.7 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listenertype or (2) currentlistener parameter to mondetail.jsp or ArraySQL parameter to (3) mondetail.jsp, (4) jamonadmin.jsp, (5) sql.jsp, or (6) exceptions.jsp.

    Published: 31 Jan 2014
    5
    Medium

    CVE-2013-6727

    Last Modified: 11 Apr 2025

    The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 31 Jan 2014
    7.1
    High

    CVE-2014-0757

    Last Modified: 22 Aug 2025

    Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.

    Published: 31 Jan 2014
    6.9
    Medium

    CVE-2014-0038

    Last Modified: 11 Apr 2025

    The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.

    Published: 31 Jan 2014
    6.8
    Medium

    CVE-2014-0054

    Last Modified: 12 Apr 2025

    The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152, CVE-2013-7315, and CVE-2013-6429.

    Published: 31 Jan 2014
    5
    Medium

    CVE-2014-0364

    Last Modified: 12 Apr 2025

    The ParseRoster component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify the from attribute of a roster-query IQ stanza, which allows remote attackers to spoof IQ responses via a crafted attribute.

    Published: 31 Jan 2014
    4.3
    Medium

    CVE-2014-1869

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters (aka loaderInfo.parameters).

    Published: 31 Jan 2014
    5
    Medium

    CVE-2014-3465

    Last Modified: 12 Apr 2025

    The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted X.509 certificate, related to a missing LDAP description for an OID when printing the DN.

    Published: 31 Jan 2014
    6
    Medium

    CVE-2014-1610

    Last Modified: 11 Apr 2025

    MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the page parameter to includes/media/DjVu.php; (2) the w parameter (aka width field) to thumb.php, which is not properly handled by includes/media/PdfHandler_body.php; and possibly unspecified vectors in (3) includes/media/Bitmap.php and (4) includes/media/ImageHandler.php.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2013-7303

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote attackers to inject arbitrary web script or HTML via the author name field.

    Published: 30 Jan 2014