7.5
    High

    CVE-2014-9448

    Last Modified: 10 Nov 2014

    Buffer overflow in Mini-stream RM-MP3 Converter 3.1.2.1.2010.03.30 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long string in a WAX file.

    Source:ZoRLu Bugrahan
    Published:2 Jan 2015
    7.5
    High

    CVE-2014-9445

    Last Modified: 30 Dec 2014

    SQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to execute arbitrary SQL commands via the create parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks by creating a file that generates an error. NOTE: this issue was originally incorrectly mapped to CVE-2014-1137; see CVE-2014-1137 for more information.

    Source:TaurusOmar
    Published:2 Jan 2015
    7.5
    High

    CVE-2014-9440

    Last Modified: 30 Dec 2014

    SQL injection vulnerability in browse.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:Manish Tanwar
    Published:2 Jan 2015
    4.3
    Medium

    CVE-2014-9439

    Last Modified: 30 Dec 2014

    Cross-site scripting (XSS) vulnerability in Easy File Sharing Web Server 6.8 allows remote attackers to inject arbitrary web script or HTML via the username field during registration, which is not properly handled by forum.ghp.

    Source:Sick Psycko
    Published:2 Jan 2015
    5
    Medium

    CVE-2014-9436

    Last Modified: 23 Dec 2014

    Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files via a \\\\ (four backslashes) in the fileName parameter to getRdsLogFile.

    Source:Bernhard Mueller
    Published:2 Jan 2015
    6.5
    Medium

    CVE-2014-9435

    Last Modified: 1 Jan 2015

    Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL commands via the (1) sectionID parameter to admin/managersection.php, (2) userID parameter to admin/edituser.php, (3) username parameter to admin/admin.php, or (4) title parameter to admin/managerrelated.php.

    Source:Steffen Rösemann
    Published:2 Jan 2015
    3.5
    Low

    CVE-2014-9434

    Last Modified: 1 Jan 2015

    Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.73 allows remote authenticated users to inject arbitrary web script or HTML via the title parameter.

    Source:Steffen Rösemann
    Published:2 Jan 2015
    2.1
    Low

    CVE-2014-9418

    Last Modified: 20 May 2019

    The eSpace Meeting ActiveX control (eSpaceStatusCtrl.dll) in Huawei eSpace Desktop before V200R001C03 allows local users to cause a denial of service (memory overflow) via unspecified vectors.

    Source:LiquidWorm
    Published:24 Dec 2014
    2.1
    Low

    CVE-2014-9417

    Last Modified: 20 May 2019

    The Meeting component in Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted image.

    Source:LiquidWorm
    Published:24 Dec 2014
    4.4
    Medium

    CVE-2014-9416

    Last Modified: 20 May 2019

    Multiple untrusted search path vulnerabilities in Huawei eSpace Desktop before V200R003C00 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) mfc71enu.dll, (2) mfc71loc.dll, (3) tcapi.dll, or (4) airpcap.dll.

    Source:LiquidWorm
    Published:24 Dec 2014
    1.9
    Low

    CVE-2014-9415

    Last Modified: 20 May 2019

    Huawei eSpace Desktop before V100R001C03 allows local users to cause a denial of service (program exit) via a crafted QES file.

    Source:LiquidWorm
    Published:24 Dec 2014
    4.3
    Medium

    CVE-2014-9412

    Last Modified: 23 Dec 2014

    Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.1 allow remote attackers to inject arbitrary web script or HTML via (1) an arbitrary parameter to roma/jsp/debug/debug.jsp or (2) an arbitrary parameter in a debug.DumpAll action to nps/servlet/webacc, a different issue than CVE-2014-5216.

    Source:SEC Consult
    Published:23 Dec 2014
    9.8
    Critical

    CVE-2014-9390

    Last Modified: 21 Nov 2024

    Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before 08-12-2014; libgit2 all versions up to 0.21.2; Egit all versions before 08-12-2014; and JGit all versions before 08-12-2014 allow remote Git servers to execute arbitrary commands via a tree containing a crafted .git/config file with (1) an ignorable Unicode codepoint, (2) a git~1/config representation, or (3) mixed case that is improperly handled on a case-insensitive filesystem.

    Published:18 Dec 2014
    5
    Medium

    CVE-2014-9350

    Last Modified: 24 Nov 2014

    TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of service (httpd crash) via vectors involving a "new" value in the isNew parameter to PingIframeRpm.htm.

    Source:LiquidWorm
    Published:8 Dec 2014
    4.3
    Medium

    CVE-2014-9349

    Last Modified: 17 Dec 2014

    Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) nom or (2) user_agent parameter to admin/robots.php.

    Source:ZoRLu Bugrahan
    Published:8 Dec 2014
    7.5
    High

    CVE-2014-9348

    Last Modified: 17 Dec 2014

    SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote attackers to execute arbitrary SQL commands via the robot parameter to admin/robots.php.

    Source:ZoRLu Bugrahan
    Published:8 Dec 2014
    7.5
    High

    CVE-2014-9347

    Last Modified: 25 Nov 2014

    SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL commands via the words_exact parameter.

    Source:bard
    Published:8 Dec 2014
    7.5
    High

    CVE-2014-9345

    Last Modified: 4 Dec 2014

    SQL injection vulnerability in Guruperl.net Advertise With Pleasure! Professional (aka AWP PRO) 6.6 and earlier allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a list_zone action to cgi/client.cgi.

    Source:Robert Cooper
    Published:8 Dec 2014
    6.8
    Medium

    CVE-2014-9344

    Last Modified: 19 Nov 2014

    Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authentication of administrators for requests that add a new admin account via a submit action in the admin/accounts/create uri to snowfox/.

    Source:LiquidWorm
    Published:8 Dec 2014
    6.8
    Medium

    CVE-2014-9331

    Last Modified: 3 Feb 2015

    Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via an addUser action to STATE_ID/1417736606982/roleMgmt.do.

    Source:Mohamed Idris
    Published:4 Feb 2015
    7.8
    High

    CVE-2014-9322

    Last Modified: 11 Jul 2018

    arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.

    Source:Ren Kimura
    Published:15 Dec 2014
    8.8
    High

    CVE-2014-9312

    Last Modified: 3 Feb 2015

    Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.

    Source:Kacper Szurek
    Published:28 Aug 2017
    3.5
    Low

    CVE-2014-9311

    Last Modified: 26 Sept 2016

    Cross-site scripting (XSS) vulnerability in admin.php in the Shareaholic plugin before 7.6.1.0 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the location[id] parameter in a shareaholic_add_location action to wp-admin/admin-ajax.php.

    Source:Kacper Szurek
    Published:14 Apr 2015
    6.5
    Medium

    CVE-2014-9308

    Last Modified: 13 Apr 2018

    Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka WordPress Shopping Cart) plugin before 3.0.9 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in products/banners/.

    Source:Kacper Szurek
    Published:15 Jan 2015
    6.5
    Medium

    CVE-2014-9305

    Last Modified: 3 Dec 2014

    SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin before 1.5.2 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a shortcode_products_table action to wp-admin/admin-ajax.php.

    Source:Kacper Szurek
    Published:8 Dec 2014
    7.5
    High

    CVE-2014-9304

    Last Modified: 28 Feb 2014

    Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

    Source:SEC Consult
    Published:7 Dec 2014
    7.8
    High

    CVE-2014-9303

    Last Modified: 2 Dec 2014

    EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a URL starting with an ASCII character o through z or A through D, different vectors than CVE-2014-8868.

    Source:RedTeam Pentesting
    Published:7 Dec 2014
    5
    Medium

    CVE-2014-9302

    Last Modified: 17 Nov 2016

    Server-side request forgery (SSRF) vulnerability in the cmisbrowser servlet in Content Management Interoperability Service (CMIS) in Alfresco Community Edition 5.0.a and earlier allows remote attackers to trigger outbound requests via a crafted URI in the url parameter.

    Source:V. Paulikas
    Published:7 Dec 2014
    6.4
    Medium

    CVE-2014-9301

    Last Modified: 17 Nov 2016

    Server-side request forgery (SSRF) vulnerability in the proxy servlet in Alfresco Community Edition before 5.0.a allows remote attackers to trigger outbound requests to intranet servers, conduct port scans, and read arbitrary files via a crafted URI in the endpoint parameter.

    Source:V. Paulikas
    Published:7 Dec 2014
    7.5
    High

    CVE-2014-9295

    Last Modified: 12 Apr 2025

    Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (1) the crypto_recv function when the Autokey Authentication feature is used, (2) the ctl_putdata function, and (3) the configure function.

    Published:19 Dec 2014
    6.8
    Medium

    CVE-2014-9265

    Last Modified: 19 Jan 2015

    Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:Praveen Darshanam
    Published:8 Dec 2014
    8.2
    High

    CVE-2014-9262

    Last Modified: 26 Sept 2016

    The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.

    Source:Kacper Szurek
    Published:7 Aug 2017
    5
    Medium

    CVE-2014-9261

    Last Modified: 10 Mar 2015

    The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.php.

    Source:Kacper Szurek
    Published:23 Mar 2015
    8.8
    High

    CVE-2014-9260

    Last Modified: 6 Mar 2015

    The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.

    Source:Kacper Szurek
    Published:7 Aug 2017
    6.5
    Medium

    CVE-2014-9258

    Last Modified: 15 Dec 2014

    SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to execute arbitrary SQL commands via the condition parameter.

    Source:Kacper Szurek
    Published:19 Dec 2014
    7.5
    High

    CVE-2014-9254

    Last Modified: 24 Nov 2016

    bb_func_unsub.php in MiniBB 3.1 before 20141127 uses an incorrect regular expression, which allows remote attackers to conduct SQl injection attacks via the code parameter in an unsubscribe action to index.php.

    Source:Kacper Szurek
    Published:31 Dec 2014
    4.3
    Medium

    CVE-2014-9243

    Last Modified: 17 Nov 2014

    Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to wb/admin/admintools/tool.php or (2) section_id parameter to edit_module_files.php, (3) news/add_post.php, (4) news/modify_group.php, (5) news/modify_post.php, or (6) news/modify_settings.php in wb/modules/.

    Source:Manuel García Cárdenas
    Published:3 Dec 2014
    7.5
    High

    CVE-2014-9242

    Last Modified: 17 Nov 2014

    SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Source:Manuel García Cárdenas
    Published:3 Dec 2014
    4.3
    Medium

    CVE-2014-9241

    Last Modified: 13 Nov 2014

    Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to report.php, (2) signature parameter in a do_editsig action to usercp.php, or (3) title parameter in the style-templates module in an edit_template action or (4) file parameter in the config-languages module in an edit action to admin/index.php.

    Source:smash
    Published:3 Dec 2014
    7.5
    High

    CVE-2014-9240

    Last Modified: 13 Nov 2014

    SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.

    Source:smash
    Published:3 Dec 2014
    7.5
    High

    CVE-2014-9237

    Last Modified: 17 Nov 2014

    SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element in a SOAP request.

    Source:Onur Alanbel (BGA)
    Published:3 Dec 2014
    4.3
    Medium

    CVE-2014-9236

    Last Modified: 17 Nov 2014

    Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) photographer_id or (2) _crumb parameter.

    Source:Manuel García Cárdenas
    Published:3 Dec 2014
    6.5
    Medium

    CVE-2014-9235

    Last Modified: 17 Nov 2014

    Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.

    Source:Manuel García Cárdenas
    Published:3 Dec 2014
    7.2
    High

    CVE-2014-9226

    Last Modified: 26 Jan 2015

    The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors.

    Source:SEC Consult
    Published:21 Jan 2015
    4
    Medium

    CVE-2014-9225

    Last Modified: 26 Jan 2015

    The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to obtain sensitive server information via unspecified vectors.

    Source:SEC Consult
    Published:21 Jan 2015
    3.5
    Low

    CVE-2014-9224

    Last Modified: 26 Jan 2015

    Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Source:SEC Consult
    Published:21 Jan 2015
    10
    Critical

    CVE-2014-9222

    Last Modified: 12 Apr 2025

    AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.

    Published:24 Dec 2014
    4.3
    Medium

    CVE-2014-9219

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the redirection feature in url.php in phpMyAdmin 4.2.x before 4.2.13.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published:8 Dec 2014
    5
    Medium

    CVE-2014-9218

    Last Modified: 15 Dec 2014

    libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows remote attackers to cause a denial of service (resource consumption) via a long password.

    Source:Javer Nieto & Andres Rojas
    Published:8 Dec 2014
    7.5
    High

    CVE-2014-9215

    Last Modified: 5 Dec 2014

    SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to execute arbitrary SQL commands via the email parameter in the register page to index.php. NOTE: the email parameter in the forget page vector is already covered by CVE-2012-4034.2.

    Source:Tran Dinh Tien
    Published:5 Dec 2014