6.8
    Medium

    CVE-2014-5023

    Last Modified: 8 Jul 2014

    Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.

    Source:drone
    Published:22 Jul 2014
    9.8
    Critical

    CVE-2014-5007

    Last Modified: 25 Jan 2018

    Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows remote attackers to write to and execute arbitrary files as SYSTEM via a .. (dot dot) in the filename parameter.

    Source:Pedro Ribeiro
    Published:17 Jan 2020
    7.5
    High

    CVE-2014-5006

    Last Modified: 25 Jan 2018

    Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter to mdm/mdmLogUploader.

    Source:Pedro Ribeiro
    Published:21 Oct 2014
    7.5
    High

    CVE-2014-5005

    Last Modified: 25 Jan 2018

    Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrary code via a .. (dot dot) in the fileName parameter in an LFU action to statusUpdate.

    Source:Pedro Ribeiro
    Published:21 Oct 2014
    6.5
    Medium

    CVE-2014-4977

    Last Modified: 17 May 2016

    Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id parameter in the changeUnit function, (3) methodDetail parameter in the methodDetail function, or (4) xcNetworkDetail parameter in the xcNetworkDetail function in d4d/exporters.php.

    Source:Metasploit
    Published:16 Jul 2014
    7.2
    High

    CVE-2014-4971

    Last Modified: 22 Jul 2014

    Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted address in an IOCTL call, related to (1) the MQAC.sys driver in the MQ Access Control subsystem and (2) the BthPan.sys driver in the Bluetooth Personal Area Networking subsystem.

    Source:KoreLogic
    Published:26 Jul 2014
    8.8
    High

    CVE-2014-4968

    Last Modified: 16 Jul 2014

    The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for Android allow remote attackers to execute arbitrary code via a crafted web site, a related issue to CVE-2012-6636.

    Source:c0otlass
    Published:12 Feb 2020
    4.3
    Medium

    CVE-2014-4965

    Last Modified: 14 Jul 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) customername parameter to central/orders/searchcriteria.action; (2) productname, (3) availability, or (4) status parameter to central/catalog/productlist.action; or unspecified vectors in (5) WebContent/orders/orderlist.jsp.

    Source:SEC Consult
    Published:15 Jul 2014
    6.8
    Medium

    CVE-2014-4964

    Last Modified: 14 Jul 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in Shopizer 1.1.5 and earlier allow remote attackers to hijack the authentication of users for requests that (1) modify customer settings or hijack the authentication of administrators for requests that change (2) customer passwords, (3) shop configuration, or (4) product details, as demonstrated by (5) modify a product's price via a crafted request to central/catalog/saveproduct.action or (6) creating a product review via a crafted request to shop/product/createReview.action.

    Source:SEC Consult
    Published:15 Jul 2014
    6.8
    Medium

    CVE-2014-4963

    Last Modified: 14 Jul 2014

    Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.

    Source:SEC Consult
    Published:15 Jul 2014
    6.4
    Medium

    CVE-2014-4962

    Last Modified: 14 Jul 2014

    Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be subtracted from the total cost.

    Source:SEC Consult
    Published:15 Jul 2014
    7.5
    High

    CVE-2014-4960

    Last Modified: 20 Dec 2016

    Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

    Source:Pham Van Khanh
    Published:21 Jul 2014
    6.5
    Medium

    CVE-2014-4944

    Last Modified: 16 Jan 2016

    Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) categoryid or (2) pdfid parameter to wp-admin/admin.php.

    Source:Claudio Viviani
    Published:14 Jul 2014
    6.9
    Medium

    CVE-2014-4943

    Last Modified: 4 Mar 2015

    The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.

    Source:Emeric Nasi
    Published:16 Jul 2014
    5
    Medium

    CVE-2014-4940

    Last Modified: 18 Jan 2016

    Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.

    Source:Anant Shrivastava
    Published:11 Jul 2014
    6.5
    Medium

    CVE-2014-4939

    Last Modified: 17 Jan 2016

    SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the enl-add-new page to wp-admin/admin.php.

    Source:Anant Shrivastava
    Published:11 Jul 2014
    7.5
    High

    CVE-2014-4938

    Last Modified: 17 Jan 2016

    SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in the wrp-add-new page to wp-admin/admin.php.

    Source:Anant Shrivastava
    Published:11 Jul 2014
    5
    Medium

    CVE-2014-4937

    Last Modified: 24 Oct 2016

    Directory traversal vulnerability in includes/bookx_export.php BookX plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Anant Shrivastava
    Published:11 Jul 2014
    9.3
    Critical

    CVE-2014-4936

    Last Modified: 23 Mar 2017

    The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle attackers to execute arbitrary code by spoofing the update server and uploading an executable.

    Source:Metasploit
    Published:16 Dec 2014
    7.8
    High

    CVE-2014-4927

    Last Modified: 18 Jul 2014

    Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.

    Source:Yuval tisf Nativ
    Published:24 Jul 2014
    9.8
    Critical

    CVE-2014-4912

    Last Modified: 8 Jul 2014

    An Arbitrary File Upload issue was discovered in Frog CMS 0.9.5 due to lack of extension validation.

    Source:Javid Hussain
    Published:22 Mar 2018
    7.5
    High

    CVE-2014-4880

    Last Modified: 24 Nov 2014

    Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote attackers to execute arbitrary code via an RTSP PLAY request with a long Authorization header.

    Source:Metasploit
    Published:8 Dec 2014
    4
    Medium

    CVE-2014-4874

    Last Modified: 25 Jan 2018

    BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment page.

    Source:Pedro Ribeiro
    Published:10 Oct 2014
    6.5
    Medium

    CVE-2014-4873

    Last Modified: 25 Jan 2018

    SQL injection vulnerability in TrackItWeb/Grid/GetData in BMC Track-It! 11.3.0.355 allows remote authenticated users to execute arbitrary SQL commands via crafted POST data.

    Source:Pedro Ribeiro
    Published:10 Oct 2014
    7.5
    High

    CVE-2014-4872

    Last Modified: 21 Oct 2014

    BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2) ConfigurationService.

    Source:Metasploit
    Published:10 Oct 2014
    6.8
    Medium

    CVE-2014-4865

    Last Modified: 15 Sept 2014

    Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attackers to hijack the authentication of arbitrary users.

    Source:William Costa
    Published:10 Sept 2014
    7.5
    High

    CVE-2014-4852

    Last Modified: 15 Jan 2016

    SQL injection vulnerability in admin/uploads.php in The Digital Craft AtomCMS, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Jagriti Sahu
    Published:10 Jul 2014
    7.5
    High

    CVE-2014-4741

    Last Modified: 15 Jan 2016

    SQL injection vulnerability in demo/ads.php in Artifectx xClassified 1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Lazmania61
    Published:9 Jul 2014
    7.5
    High

    CVE-2014-4736

    Last Modified: 19 Jan 2016

    SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.

    Source:High-Tech Bridge
    Published:24 Jul 2014
    7.5
    High

    CVE-2014-4725

    Last Modified: 8 Jul 2014

    The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

    Source:Metasploit
    Published:27 Jul 2014
    6.8
    Medium

    CVE-2014-4718

    Last Modified: 24 Jun 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack the authentication of administrators for requests that (1) add Super users via a request to admin/user_create.php or conduct cross-site scripting (XSS) attacks via the (2) email or (3) subject parameter in contact_form.ext.php to admin/extensions.php.

    Source:LiquidWorm
    Published:3 Jul 2014
    6.8
    Medium

    CVE-2014-4717

    Last Modified: 27 Jun 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) ssba_share_text parameter in a save action to wp-admin/options-general.php, which is not properly handled in the homepage, and unspecified vectors related to (2) Pages, (3) Posts, (4) Category/Archive pages or (5) post Excerpts.

    Source:dxw
    Published:3 Jul 2014
    6.8
    Medium

    CVE-2014-4716

    Last Modified: 25 Jun 2014

    Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authentication of unspecified victims for requests that change passwords via the Password and PasswordReEnter parameters to goform/RgSecurity.

    Source:nopesled
    Published:3 Jul 2014
    4.3
    Medium

    CVE-2014-4710

    Last Modified: 12 Jul 2015

    Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the Full Name field.

    Source:Mayuresh Dani
    Published:29 Jul 2014
    2.1
    Low

    CVE-2014-4703

    Last Modified: 2 Nov 2016

    lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.

    Source:Dawid Golunski
    Published:16 May 2014
    6.9
    Medium

    CVE-2014-4699

    Last Modified: 19 Mar 2018

    The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.

    Source:Vitaly Nikolenko
    Published:4 Jul 2014
    6.5
    Medium

    CVE-2014-4688

    Last Modified: 15 Jan 2018

    pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias action, (2) the smartmonemail value to diag_smart.php, or (3) the database value to status_rrd_graph_img.php.

    Source:absolomb
    Published:2 Jul 2014
    4.3
    Medium

    CVE-2014-4671

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on Android, Adobe AIR SDK before 14.0.0.137, and Adobe AIR SDK & Compiler before 14.0.0.137 do not properly restrict the SWF file format, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks against JSONP endpoints, and obtain sensitive information, via a crafted OBJECT element with SWF content satisfying the character-set requirements of a callback API.

    Published:8 Jul 2014
    6.8
    Medium

    CVE-2014-4663

    Last Modified: 22 Sept 2016

    TimThumb 2.8.13 and WordThumb 1.07, when Webshot (aka Webshots) is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the src parameter.

    Source:@u0x
    Published:15 Jul 2014
    9.8
    Critical

    CVE-2014-4650

    Last Modified: 27 Jun 2014

    The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

    Source:RedTeam Pentesting
    Published:23 Jun 2014
    4.3
    Medium

    CVE-2014-4645

    Last Modified: 21 Jun 2014

    Cross-site scripting (XSS) vulnerability in dhcpinfo.html in D-link DSL-2760U-E1 allows remote attackers to inject arbitrary web script or HTML via a hostname.

    Source:Yuval tisf Nativ
    Published:25 Jun 2014
    7.5
    High

    CVE-2014-4644

    Last Modified: 21 Jun 2014

    SQL injection vulnerability in superlinks.php in the superlinks plugin 1.4-2 for Cacti allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Napsterakos
    Published:25 Jun 2014
    5
    Medium

    CVE-2014-4643

    Last Modified: 12 Jun 2014

    Multiple heap-based buffer overflows in the client in Core FTP LE 2.2 build 1798 allow remote FTP servers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in a reply to a (1) USER, (2) PASS, (3) PASV, (4) SYST, (5) PWD, or (6) CDUP command.

    Source:Gabor Seljan
    Published:25 Jun 2014
    6.5
    Medium

    CVE-2014-4613

    Last Modified: 26 Feb 2014

    Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that add users via a pwg.users.add action in a request to ws.php.

    Source:killall-9
    Published:16 Mar 2018
    7.5
    High

    CVE-2014-4511

    Last Modified: 8 Jul 2014

    Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.

    Source:Metasploit
    Published:22 Jul 2014
    7.5
    High

    CVE-2014-4492

    Last Modified: 20 Jan 2015

    libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain values have the expected data type, which allows attackers to execute arbitrary code in an _networkd context via a crafted XPC message from a sandboxed app, as demonstrated by lack of verification of the XPC dictionary data type.

    Source:Google Security Research
    Published:30 Jan 2015
    6.8
    Medium

    CVE-2014-4481

    Last Modified: 12 Apr 2025

    Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

    Published:30 Jan 2015
    7.8
    High

    CVE-2014-4404

    Last Modified: 2 Dec 2014

    Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an application that provides crafted key-mapping properties.

    Source:Metasploit
    Published:18 Sept 2014
    5.8
    Medium

    CVE-2014-4378

    Last Modified: 12 Apr 2025

    CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted PDF document.

    Published:18 Sept 2014
    6.8
    Medium

    CVE-2014-4377

    Last Modified: 12 Apr 2025

    Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

    Published:18 Sept 2014