CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2014-0392

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2014-0394

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect confidentiality via unknown vectors related to Updates Environment Mgmt, a different vulnerability than CVE-2014-0395.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2014-0398

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, and 12.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Discoverer.

    Published: 15 Jan 2014
    4
    Medium

    CVE-2014-0399

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, and 6.3.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Data, Domain & Function Security.

    Published: 15 Jan 2014
    3.5
    Low

    CVE-2013-5892

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.22, and 4.3.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core.

    Published: 15 Jan 2014
    5.5
    Medium

    CVE-2014-0367

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Hyperion Essbase Administration Services component in Oracle Hyperion 11.1.2.1, 11.1.2.2, and 11.1.2.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Admin Console.

    Published: 15 Jan 2014
    3.5
    Low

    CVE-2014-0383

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.2.0 and 11.1.2.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Identity Console.

    Published: 15 Jan 2014
    4.3
    Medium

    CVE-2014-0389

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle iLearning 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2014-0396

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect confidentiality via unknown vectors related to Portal - Web Services.

    Published: 15 Jan 2014
    7.1
    High

    CVE-2013-3830

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Hyperion Strategic Finance component in Oracle Hyperion 11.1.2.1 and 11.1.2.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server.

    Published: 15 Jan 2014
    4.6
    Medium

    CVE-2013-5821

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11.1 allows local users to affect confidentiality, integrity, and availability via vectors related to RPC.

    Published: 15 Jan 2014
    6.2
    Medium

    CVE-2013-5834

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to ps.

    Published: 15 Jan 2014
    3.5
    Low

    CVE-2013-5764

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, and 12.1.0.1 allows remote authenticated users to affect availability via unknown vectors.

    Published: 15 Jan 2014
    7.5
    High

    CVE-2013-5785

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.6, 11.1.1.7, and 11.1.2.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security and Authentication.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2013-5795

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2, and 12.2.3 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.

    Published: 15 Jan 2014
    4.9
    Medium

    CVE-2013-5833

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8 and 9 allows local users to affect availability via unknown vectors related to Filesystem.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2013-5853

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, and 12.1.0.1 allows remote attackers to affect availability via unknown vectors.

    Published: 15 Jan 2014
    4
    Medium

    CVE-2013-5858

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2015-0370.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2013-5869

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebCenter Portal component in Oracle Fusion Middleware 11.1.1.6.0, 11.1.1.7.0, and 11.1.1.8.0 allows remote attackers to affect confidentiality via unknown vectors related to Page Service.

    Published: 15 Jan 2014
    2.1
    Low

    CVE-2013-5872

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to Name Service Cache Daemon (NSCD).

    Published: 15 Jan 2014
    1.7
    Low

    CVE-2013-5874

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, and 12.2.2 allows local users to affect confidentiality via unknown vectors related to Logging.

    Published: 15 Jan 2014
    2.7
    Low

    CVE-2013-5875

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11.1 allows local users to affect integrity and availability via vectors related to Role Based Access Control (RBAC).

    Published: 15 Jan 2014
    4.9
    Medium

    CVE-2013-5876

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via unknown vectors related to Kernel, a different vulnerability than CVE-2014-0447.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2013-5877

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.0, and 12.2.1 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2013-5880

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.

    Published: 15 Jan 2014
    3.2
    Low

    CVE-2013-5883

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8 allows local users to affect integrity and availability via unknown vectors related to Kernel.

    Published: 15 Jan 2014
    4.3
    Medium

    CVE-2013-5886

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote attackers to affect integrity via unknown vectors related to Common Application Objects.

    Published: 15 Jan 2014
    5.5
    Medium

    CVE-2013-5890

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Payroll component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, 12.1.3, and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Exception Reporting.

    Published: 15 Jan 2014
    2.6
    Low

    CVE-2013-5808

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle iPlanet Web Proxy Server component in Oracle Fusion Middleware 4.0 allows remote attackers to affect confidentiality via unknown vectors related to Administration.

    Published: 15 Jan 2014
    3.5
    Low

    CVE-2013-5868

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vulnerability than CVE-2013-5871 and CVE-2014-0444.

    Published: 15 Jan 2014
    3.5
    Low

    CVE-2013-5871

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle AutoVue Electro-Mechanical Professional component in Oracle Supply Chain Products Suite 20.1.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Web General, a different vulnerability than CVE-2013-5868 and CVE-2014-0444.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2013-5873

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect confidentiality via unknown vectors related to Integration Broker.

    Published: 15 Jan 2014
    6.8
    Medium

    CVE-2013-5879

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Maintenance.

    Published: 15 Jan 2014
    1.7
    Low

    CVE-2013-5885

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 11.1 allows local users to affect integrity via unknown vectors related to Audit.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2013-6466

    Last Modified: 11 Apr 2025

    Openswan 2.6.39 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.

    Published: 15 Jan 2014
    5
    Medium

    CVE-2013-6467

    Last Modified: 11 Apr 2025

    Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads.

    Published: 15 Jan 2014
    9.3
    Critical

    CVE-2014-1202

    Last Modified: 11 Apr 2025

    The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.

    Published: 15 Jan 2014
    4.3
    Medium

    CVE-2014-0028

    Last Modified: 11 Apr 2025

    libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.

    Published: 15 Jan 2014
    7.5
    High

    CVE-2014-8636

    Last Modified: 12 Apr 2025

    The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.

    Published: 15 Jan 2014
    7.1
    High

    CVE-2014-0617

    Last Modified: 11 Apr 2025

    Juniper Junos 10.4S before 10.4S15, 10.4R before 10.4R16, 11.4 before 11.4R9, and 12.1R before 12.1R7 on SRX Series service gateways allows remote attackers to cause a denial of service (flowd crash) via a crafted IP packet.

    Published: 14 Jan 2014
    6.8
    Medium

    CVE-2013-7107

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.

    Published: 14 Jan 2014
    4
    Medium

    CVE-2014-0031

    Last Modified: 11 Apr 2025

    The (1) ListNetworkACL and (2) listNetworkACLLists APIs in Apache CloudStack before 4.2.1 allow remote authenticated users to list network ACLS for other users via a crafted request.

    Published: 14 Jan 2014
    7.1
    High

    CVE-2014-0613

    Last Modified: 11 Apr 2025

    The XNM command processor in Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 before 12.1X46-D10, 12.2 before 12.2R7, 12.3 before 12.3R5, 13.1 before 13.1R3-S1, 13.2 before 13.2R2-S2, and 13.3 before 13.3R1, when xnm-ssl or xnm-clear-text is enabled, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

    Published: 14 Jan 2014
    7.2
    High

    CVE-2014-0615

    Last Modified: 11 Apr 2025

    Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 before 12.1X46-D10, 12.2 before 12.2R7, 12.3 before 12.3R5, 13.1 before 13.1R3-S1, 13.2 before 13.2R2, and 13.3 before 13.3R1 allows local users to gain privileges via vectors related to "certain combinations of Junos OS CLI commands and arguments."

    Published: 14 Jan 2014
    7.1
    High

    CVE-2014-0616

    Last Modified: 11 Apr 2025

    Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 before 12.1X46-D10, 12.2 before 12.2R7, 12.3 before 12.3R4-S2, 13.1 before 13.1R3-S1, 13.2 before 13.2R2, and 13.3 before 13.3R1 allows remote attackers to cause a denial of service (rdp crash) via a large BGP UPDATE message which immediately triggers a withdraw message to be sent, as demonstrated by a long AS_PATH and a large number of BGP Communities.

    Published: 14 Jan 2014
    2.8
    Low

    CVE-2013-6398

    Last Modified: 11 Apr 2025

    The virtual router in Apache CloudStack before 4.2.1 does not preserve the source restrictions in firewall rules after being restarted, which allows remote attackers to bypass intended restrictions via a request.

    Published: 14 Jan 2014
    6.5
    Medium

    CVE-2013-7106

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the (1) display_nav_table, (2) page_limit_selector, (3) print_export_link, or (4) page_num_selector function in cgi/cgiutils.c; (5) status_page_num_selector function in cgi/status.c; or (6) display_command_expansion function in cgi/config.c. NOTE: this can be exploited without authentication by leveraging CVE-2013-7107.

    Published: 14 Jan 2014
    6.9
    Medium

    CVE-2013-6123

    Last Modified: 11 Apr 2025

    Multiple array index errors in drivers/media/video/msm/server/msm_cam_server.c in the MSM camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to gain privileges by leveraging camera device-node access, related to the (1) msm_ctrl_cmd_done, (2) msm_ioctl_server, and (3) msm_server_send_ctrl functions.

    Published: 14 Jan 2014
    5.3
    Medium

    CVE-2013-4578

    Last Modified: 20 Apr 2025

    jarsigner in OpenJDK and Oracle Java SE before 7u51 allows remote attackers to bypass a code-signing protection mechanism and inject unsigned bytecode into a signed JAR file by leveraging improper file validation.

    Published: 14 Jan 2014
    6.8
    Medium

    CVE-2013-5870

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u45 and JavaFX 2.2.45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to JavaFX.

    Published: 14 Jan 2014