CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2014-1837

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors related to "checking new comments."

    Published: 30 Jan 2014
    9.3
    Critical

    CVE-2013-7246

    Last Modified: 11 Apr 2025

    Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers to execute arbitrary code via a long string, as exploited in the wild in January 2014.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2014-1611

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Anonymous Posting module 7.x-1.2 and 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the contact name field.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2014-1612

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in login.esp in the Web Management Interface in Media5 Mediatrix 4402 VoIP Gateway with firmware Dgw 1.1.13.186 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2014-0793

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) website or (2) latitude parameter in a comment to the default URI.

    Published: 30 Jan 2014
    3.5
    Low

    CVE-2013-0177

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2013-3084

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Belkin Model F5D8236-4 v2 router allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2013-3090

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Belkin N300 router allow remote attackers to inject arbitrary web script or HTML via the Guest Access PSK field to wireless_guest2_print.stm or other unspecified vectors.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2013-3087

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Belkin N900 router allow remote attackers to inject arbitrary web script or HTML via the (1) ssid2 parameter to wl_channel.html or (2) guest_psk parameter to wl_guest.html.

    Published: 30 Jan 2014
    7.5
    High

    CVE-2012-3000

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in sam/admin/reports/php/saveSettings.php in the (1) APM WebGUI in F5 BIG-IP LTM, GTM, ASM, Link Controller, PSM, APM, Edge Gateway, and Analytics and (2) AVR WebGUI in WebAccelerator and WOM 11.2.x before 11.2.0-HF3 and 11.2.x before 11.2.1-HF3 allow remote authenticated users to execute arbitrary SQL commands via the defaultQuery parameter.

    Published: 30 Jan 2014
    6.8
    Medium

    CVE-2014-0835

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify console Auto Update settings.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2014-0836

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2014-0837

    Last Modified: 11 Apr 2025

    The AutoUpdate process in IBM Security QRadar SIEM 7.2 MR1 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.

    Published: 30 Jan 2014
    7.5
    High

    CVE-2014-0838

    Last Modified: 11 Apr 2025

    The AutoUpdate package before 6.4 for IBM Security QRadar SIEM 7.2 MR1 and earlier allows remote attackers to execute arbitrary console commands by leveraging control of the server.

    Published: 30 Jan 2014
    4.3
    Medium

    CVE-2014-2856

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in scheduler/client.c in Common Unix Printing System (CUPS) before 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the URL path, related to the is_path_absolute function.

    Published: 30 Jan 2014
    7.5
    High

    CVE-2014-0001

    Last Modified: 11 Apr 2025

    Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

    Published: 30 Jan 2014
    7.5
    High

    CVE-2013-4887

    Last Modified: 8 Dec 2025

    SQL injection vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to execute arbitrary SQL commands via the displayid parameter.

    Published: 29 Jan 2014
    6.8
    Medium

    CVE-2013-4889

    Last Modified: 8 Dec 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new administrator via the AddUser action or (2) conduct cross-site scripting (XSS) attacks, as demonstrated by CVE-2013-4888.

    Published: 29 Jan 2014
    6.8
    Medium

    CVE-2014-1683

    Last Modified: 11 Apr 2025

    The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) name, (2) email, (3) subject, or (4) message parameter to index.php.

    Published: 29 Jan 2014
    6.5
    Medium

    CVE-2013-2747

    Last Modified: 11 Apr 2025

    The password reset feature in Courion Access Risk Management Suite Version 8 Update 9 allows remote authenticated users to bypass intended Internet Explorer usage restrictions and execute arbitrary commands by using keyboard shortcuts to navigate the file system and open a command prompt.

    Published: 29 Jan 2014
    4.3
    Medium

    CVE-2013-7318

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in BusinessFlow/login in AlgoSec Firewall Analyzer 6.4 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 29 Jan 2014
    4.3
    Medium

    CVE-2012-6086

    Last Modified: 11 Apr 2025

    libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 29 Jan 2014
    4.9
    Medium

    CVE-2013-4661

    Last Modified: 11 Apr 2025

    CiviCRM 2.0.0 through 4.2.9 and 4.3.0 through 4.3.3 does not properly enforce role-based access control (RBAC) restrictions for default custom searches, which allows remote authenticated users with the "access CiviCRM" permission to bypass intended access restrictions, as demonstrated by accessing custom contribution data without having the "access CiviContribute" permission.

    Published: 29 Jan 2014
    6.5
    Medium

    CVE-2013-4662

    Last Modified: 11 Apr 2025

    The Quick Search API in CiviCRM 4.2.0 through 4.2.9 and 4.3.0 through 4.3.3 allows remote authenticated users to bypass the validation layer and conduct SQL injection attacks via a direct request to the "second layer" of the API, related to contact.getquick.

    Published: 29 Jan 2014
    4.3
    Medium

    CVE-2013-4888

    Last Modified: 8 Dec 2025

    Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the layout parameter in the layout page.

    Published: 29 Jan 2014
    6.5
    Medium

    CVE-2013-4898

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in public/temporary/timeline/.

    Published: 29 Jan 2014
    4.3
    Medium

    CVE-2013-5092

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 29 Jan 2014
    4.3
    Medium

    CVE-2013-5005

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ajaxRequest/methodCall.do in Tripwire Enterprise 8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) m_target_class_name, (2) m_target_method_name, or (3) m_request_context_params parameters.

    Published: 29 Jan 2014
    5
    Medium

    CVE-2013-6141

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in op5 Monitor before 6.1.3 allows attackers to read arbitrary files via unknown vectors related to lack of authorization.

    Published: 29 Jan 2014
    4.3
    Medium

    CVE-2014-0681

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Identity Services Engine (ISE) 1.2 patch 2 and earlier allows remote attackers to inject arbitrary web script or HTML via a report containing a crafted URL that is not properly handled during generation of report-output pages, aka Bug ID CSCui15064.

    Published: 29 Jan 2014
    4.3
    Medium

    CVE-2014-0680

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038.

    Published: 29 Jan 2014
    4.9
    Medium

    CVE-2014-0682

    Last Modified: 11 Apr 2025

    Cisco WebEx Meetings Server allows remote authenticated users to bypass authorization checks and (1) join arbitrary meetings, or (2) terminate a meeting without having a host role, via a crafted URL, aka Bug ID CSCuj42346.

    Published: 29 Jan 2014
    6.5
    Medium

    CVE-2013-6930

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the page-navigation implementation in Cybozu Garoon 2.0.0 through 2.0.6, 2.1.0 through 2.1.3, 2.5.0 through 2.5.4, 3.0.0 through 3.0.3, 3.5.0 through 3.5.5, and 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6929.

    Published: 29 Jan 2014
    6.5
    Medium

    CVE-2013-6931

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the API in Cybozu Garoon 3.7.x before 3.7.3 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2013-6929.

    Published: 29 Jan 2014
    7.5
    High

    CVE-2013-2974

    Last Modified: 11 Apr 2025

    The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.

    Published: 29 Jan 2014
    7.5
    High

    CVE-2013-6748

    Last Modified: 11 Apr 2025

    Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6749.

    Published: 29 Jan 2014
    7.5
    High

    CVE-2013-6749

    Last Modified: 11 Apr 2025

    Buffer overflow in the ActiveX control in qp2.cab in IBM Lotus Quickr for Domino 8.5.1 before 8.5.1.42-001b allows remote attackers to execute arbitrary code via a crafted HTML document, a different vulnerability than CVE-2013-6748.

    Published: 29 Jan 2014
    7.5
    High

    CVE-2014-0810

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in JustSystems Sanshiro 2007 before update 3, 2008 before update 5, 2009 before update 6, and 2010 before update 6, and Sanshiro Viewer before 2.0.2.0, allows remote attackers to execute arbitrary code via a crafted document.

    Published: 29 Jan 2014
    10
    Critical

    CVE-2014-3007

    Last Modified: 12 Apr 2025

    Python Image Library (PIL) 1.1.7 and earlier and Pillow 2.3 might allow remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors related to CVE-2014-1932, possibly JpegImagePlugin.py.

    Published: 29 Jan 2014
    4
    Medium

    CVE-2014-0015

    Last Modified: 11 Apr 2025

    cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.

    Published: 29 Jan 2014
    4.9
    Medium

    CVE-2014-1874

    Last Modified: 12 Apr 2025

    The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security context.

    Published: 29 Jan 2014
    2.1
    Low

    CVE-2014-1933

    Last Modified: 12 Apr 2025

    The (1) JpegImagePlugin.py and (2) EpsImagePlugin.py scripts in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 uses the names of temporary files on the command line, which makes it easier for local users to conduct symlink attacks by listing the processes.

    Published: 29 Jan 2014
    4.4
    Medium

    CVE-2014-1932

    Last Modified: 12 Apr 2025

    The (1) load_djpeg function in JpegImagePlugin.py, (2) Ghostscript function in EpsImagePlugin.py, (3) load function in IptcImagePlugin.py, and (4) _copy function in Image.py in Python Image Library (PIL) 1.1.7 and earlier and Pillow before 2.3.1 do not properly create temporary files, which allow local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on the temporary file.

    Published: 29 Jan 2014
    Unknown

    CVE-2014-0025

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-1690. Reason: This candidate is a reservation duplicate of CVE-2014-1690. Notes: All CVE users should reference CVE-2014-1690 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Jan 2014
    4.3
    Medium

    CVE-2013-5094

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HTML via the cert_cn cookie parameter.

    Published: 28 Jan 2014
    10
    Critical

    CVE-2014-1681

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.102 have unknown impact and attack vectors, related to 12 "security fixes [that were not] either contributed by external researchers or particularly interesting."

    Published: 28 Jan 2014
    7.5
    High

    CVE-2013-6649

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image.

    Published: 28 Jan 2014
    7.5
    High

    CVE-2013-6487

    Last Modified: 11 Apr 2025

    Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a large Content-Length value, which triggers a buffer overflow.

    Published: 28 Jan 2014
    5
    Medium

    CVE-2013-6489

    Last Modified: 11 Apr 2025

    Integer signedness error in the MXit functionality in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (segmentation fault) via a crafted emoticon value, which triggers an integer overflow and a buffer overflow.

    Published: 28 Jan 2014
    1.9
    Low

    CVE-2014-0019

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.

    Published: 28 Jan 2014