6.5
    Medium

    CVE-2014-8498

    Last Modified: 25 Jan 2018

    SQL injection vulnerability in BulkEditSearchResult.cc in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition before 7.1 build 7105 allows remote authenticated users to execute arbitrary SQL commands via the SEARCH_ALL parameter.

    Source:Pedro Ribeiro
    Published:17 Nov 2014
    5
    Medium

    CVE-2014-8493

    Last Modified: 17 Nov 2014

    ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.

    Source:Project Zero Labs
    Published:20 Nov 2014
    4.3
    Medium

    CVE-2014-8469

    Last Modified: 17 Nov 2014

    Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

    Source:spyk2r
    Published:21 Nov 2014
    10
    Critical

    CVE-2014-8440

    Last Modified: 1 May 2015

    Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0576, CVE-2014-0581, and CVE-2014-8441.

    Source:Metasploit
    Published:11 Nov 2014
    6.8
    Medium

    CVE-2014-8429

    Last Modified: 26 Nov 2014

    Cross-site request forgery (CSRF) vulnerability in Xavoc Technocrats xEpan CMS 1.0.4.1, 1.0.4, 1.0.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts via a crafted request to the owner/users page.

    Source:High-Tech Bridge SA
    Published:28 Nov 2014
    7.8
    High

    CVE-2014-8425

    Last Modified: 25 Nov 2014

    The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.

    Source:HeadlessZeke
    Published:28 Nov 2014
    7.8
    High

    CVE-2014-8424

    Last Modified: 25 Nov 2014

    ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.

    Source:HeadlessZeke
    Published:28 Nov 2014
    10
    Critical

    CVE-2014-8423

    Last Modified: 25 Nov 2014

    Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.

    Source:HeadlessZeke
    Published:28 Nov 2014
    7.8
    High

    CVE-2014-8393

    Last Modified: 7 Sept 2010

    DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.

    Source:LiquidWorm
    Published:28 Aug 2017
    4
    Medium

    CVE-2014-8391

    Last Modified: 26 May 2015

    The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to obtain sensitive information from other users' sessions via a large number of requests.

    Source:Core Security
    Published:2 Jun 2015
    9
    Critical

    CVE-2014-8387

    Last Modified: 24 Nov 2014

    cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

    Source:Core Security
    Published:20 Nov 2014
    7.5
    High

    CVE-2014-8386

    Last Modified: 10 Dec 2014

    Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file.

    Source:Muhamad Fadzil Ramli
    Published:20 Jan 2015
    4.3
    Medium

    CVE-2014-8380

    Last Modified: 9 Jan 2017

    Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer Header in a "404 Not Found" response. NOTE: this vulnerability might exist because of a CVE-2010-2429 regression.

    Source:justpentest
    Published:21 Oct 2014
    6.5
    Medium

    CVE-2014-8375

    Last Modified: 21 Jan 2016

    SQL injection vulnerability in GBgallery.php in the GB Gallery Slideshow plugin 1.5 for WordPress allows remote administrators to execute arbitrary SQL commands via the selected_group parameter in a gb_ajax_get_group action to wp-admin/admin-ajax.php.

    Source:Claudio Viviani
    Published:21 Oct 2014
    9.8
    Critical

    CVE-2014-8361

    Last Modified: 1 Jun 2015

    The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

    Source:Metasploit
    Published:1 May 2015
    7.2
    High

    CVE-2014-8359

    Last Modified: 24 Dec 2013

    Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll in the Mobile Partner directory.

    Source:LiquidWorm
    Published:13 Nov 2014
    7.8
    High

    CVE-2014-8358

    Last Modified: 24 Dec 2013

    Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the "Mobile Partner" directory, which allows remote attackers to gain SYSTEM privileges by compromising a low privilege account and modifying Mobile Partner.exe.

    Source:LiquidWorm
    Published:11 Dec 2017
    8.8
    High

    CVE-2014-8357

    Last Modified: 13 Oct 2015

    backupsettings.html in the web administrative portal in Zhone zNID GPON 2426A before S3.0.501 places a session key in a URL, which allows remote attackers to obtain arbitrary user passwords via the sessionKey parameter in a getConfig action to backupsettings.conf.

    Source:Lyon Yang
    Published:17 Oct 2017
    8.8
    High

    CVE-2014-8356

    Last Modified: 13 Oct 2015

    The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.

    Source:Lyon Yang
    Published:21 Nov 2019
    7.8
    High

    CVE-2014-8347

    Last Modified: 28 Oct 2014

    An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.

    Source:Giuseppe D'Amore
    Published:11 Feb 2020
    9.8
    Critical

    CVE-2014-8322

    Last Modified: 3 Nov 2014

    Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.

    Source:Nick Sampanis
    Published:31 Jan 2020
    4.3
    Medium

    CVE-2014-8307

    Last Modified: 25 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in skins/default/outline.tpl in C97net Cart Engine before 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) path parameter in the "drop down TOP menu (with path)" section or (2) print_this_page variable in the footer_content_block section, as demonstrated by the QUERY_STRING to (a) index.php, (b) checkout.php, (c) contact.php, (d) detail.php, (e) distro.php, (f) newsletter.php, (g) page.php, (h) profile.php, (i) search.php, (j) sitemap.php, (k) task.php, or (l) tell.php.

    Source:Quantum Leap
    Published:16 Oct 2014
    7.5
    High

    CVE-2014-8306

    Last Modified: 25 Sept 2014

    SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attackers to execute arbitrary SQL commands via the item_id variable, as demonstrated by the (1) item_id[0] or (2) item_id[] parameter.

    Source:Quantum Leap
    Published:16 Oct 2014
    6.4
    Medium

    CVE-2014-8305

    Last Modified: 25 Sept 2014

    Open redirect vulnerability in the redir function in includes/function.php in C97net Cart Engine before 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header to (1) index.php, (2) cart.php, (3) msg.php, or (4) page.php.

    Source:Quantum Leap
    Published:16 Oct 2014
    7.5
    High

    CVE-2014-8295

    Last Modified: 3 Oct 2014

    SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parameter.

    Source:wishnusakti
    Published:15 Oct 2014
    5
    Medium

    CVE-2014-8275

    Last Modified: 12 Apr 2025

    OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, related to crypto/asn1/a_verify.c, crypto/dsa/dsa_asn1.c, crypto/ecdsa/ecs_vrf.c, and crypto/x509/x_all.c.

    Published:5 Jan 2015
    5
    Medium

    CVE-2014-8272

    Last Modified: 13 Jan 2015

    The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.

    Source:Yong Chuan_ Koh
    Published:19 Dec 2014
    7.5
    High

    CVE-2014-8244

    Last Modified: 12 Apr 2025

    Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6200 devices; before 1.1.40 build 160989 on EA6300, EA6400, EA6500, and EA6700 devices; and before 1.1.42 build 161129 on EA6900 devices allows remote attackers to obtain sensitive information or modify data via a JNAP action in a JNAP/ HTTP request.

    Published:1 Nov 2014
    7.5
    High

    CVE-2014-8147

    Last Modified: 25 Jan 2018

    The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 uses an integer data type that is inconsistent with a header file, which allows remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text.

    Source:Pedro Ribeiro
    Published:5 May 2015
    7.5
    High

    CVE-2014-8146

    Last Modified: 25 Jan 2018

    The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) before 55.1 does not properly track directionally isolated pieces of text, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text.

    Source:Pedro Ribeiro
    Published:5 May 2015
    7.5
    High

    CVE-2014-8142

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys within the serialized properties of an object, a different vulnerability than CVE-2004-1019.

    Published:18 Dec 2014
    4.3
    Medium

    CVE-2014-8110

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web based administration console in Apache ActiveMQ 5.x before 5.10.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published:5 Feb 2015
    6.8
    Medium

    CVE-2014-8008

    Last Modified: 18 Aug 2015

    Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authenticated users to read arbitrary files via a full pathname in an API command, aka Bug ID CSCur49414.

    Source:Bernhard Mueller
    Published:22 Jan 2015
    Low

    CVE-2014-7969

    Last Modified: 26 Sept 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8739. Reason: This candidate is a duplicate of CVE-2014-8739. Notes: All CVE users should reference CVE-2014-8739 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Gianni Angelozzi
    Published:11 Feb 2020
    4.6
    Medium

    CVE-2014-7951

    Last Modified: 21 Apr 2015

    Directory traversal vulnerability in the Android debug bridge (aka adb) in Android 4.0.4 allows physically proximate attackers with a direct connection to the target Android device to write to arbitrary files owned by system via a .. (dot dot) in the tar archive headers.

    Source:Imre Rad
    Published:20 Feb 2020
    9.8
    Critical

    CVE-2014-7920

    Last Modified: 20 Apr 2025

    mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.

    Published:13 Apr 2017
    6.8
    Medium

    CVE-2014-7912

    Last Modified: 12 Apr 2025

    The get_option function in dhcp.c in dhcpcd before 6.2.0, as used in dhcpcd 5.x in Android before 5.1 and other products, does not validate the relationship between length fields and the amount of data, which allows remote DHCP servers to execute arbitrary code or cause a denial of service (memory corruption) via a large length value of an option in a DHCPACK message.

    Published:30 Jul 2015
    7.2
    High

    CVE-2014-7911

    Last Modified: 12 Apr 2025

    luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deserialization will result in an object that met the requirements for serialization, which allows attackers to execute arbitrary code via a crafted finalize method for a serialized object in an ArrayMap Parcel within an intent sent to system_service, as demonstrated by the finalize method of android.os.BinderProxy, aka Bug 15874291.

    Published:15 Dec 2014
    7.5
    High

    CVE-2014-7910

    Last Modified: 25 Sept 2014

    Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Source:Shaun Colley
    Published:18 Nov 2014
    9
    Critical

    CVE-2014-7884

    Last Modified: 16 Mar 2015

    Multiple unspecified vulnerabilities in HP ArcSight Logger before 6.0P1 have unknown impact and remote authenticated attack vectors.

    Source:Horoszkiewicz Julian ISP_
    Published:14 Mar 2015
    5
    Medium

    CVE-2014-7883

    Last Modified: 31 Oct 2016

    HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information by reading the headers of a response.

    Source:Hans-Martin Muench
    Published:15 Feb 2015
    7.2
    High

    CVE-2014-7872

    Last Modified: 20 May 2015

    Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges by connecting to the server.

    Source:Jeremy Brown
    Published:9 Jun 2015
    7.5
    High

    CVE-2014-7868

    Last Modified: 10 Nov 2014

    Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) OPM_BVNAME parameter in a Delete operation to the APMBVHandler servlet or (2) query parameter in a compare operation to the DataComparisonServlet servlet.

    Source:Pedro Ribeiro
    Published:4 Dec 2014
    7.5
    High

    CVE-2014-7866

    Last Modified: 10 Nov 2014

    Multiple directory traversal vulnerabilities in ZOHO ManageEngine OpManager 8 (build 88xx) through 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to write and execute arbitrary files via a .. (dot dot) in the (1) fileName parameter to the MigrateLEEData servlet or (2) zipFileName parameter in a downloadFileFromProbe operation to the MigrateCentralData servlet.

    Source:Pedro Ribeiro
    Published:10 Dec 2014
    7.5
    High

    CVE-2014-7864

    Last Modified: 25 Jan 2018

    Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpManager 8 through 11.5 build 11400 and IT360 10.5 and earlier allow remote attackers and remote authenticated users to execute arbitrary SQL commands via the (1) customerName or (2) serverRole parameter in a standbyUpdateInCentral operation to servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

    Source:Pedro Ribeiro
    Published:4 Feb 2015
    7.5
    High

    CVE-2014-7863

    Last Modified: 25 Jan 2018

    The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, OpManager 8 through 11.5 build 11400, and IT360 10.5 and earlier does not properly restrict access, which allows remote attackers and remote authenticated users to (1) read arbitrary files via the fileName parameter in a copyfile operation or (2) obtain sensitive information via a directory listing in a listdirectory operation to servlet/FailOverHelperServlet.

    Source:Pedro Ribeiro
    Published:8 Feb 2020
    9.8
    Critical

    CVE-2014-7862

    Last Modified: 25 Jan 2018

    The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.

    Source:Pedro Ribeiro
    Published:4 Jan 2018
    7.2
    High

    CVE-2014-7822

    Last Modified: 4 Sept 2016

    The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted splice system call, as demonstrated by use of a file descriptor associated with an ext4 filesystem.

    Source:Emeric Nasi
    Published:28 Jan 2015
    5
    Medium

    CVE-2014-7816

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.

    Published:28 Oct 2014
    6.5
    Medium

    CVE-2014-7289

    Last Modified: 26 Jan 2015

    SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.

    Source:SEC Consult
    Published:21 Jan 2015