7.5
    High

    CVE-2014-3871

    Last Modified: 6 Nov 2017

    Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter. NOTE: the b parameter to index.php vector is already covered by CVE-2006-3823.

    Source:Esac
    Published:27 May 2014
    8.8
    High

    CVE-2014-3868

    Last Modified: 11 Jan 2016

    Multiple SQL injection vulnerabilities in ZeusCart 4.x.

    Source:Kenny Mathis
    Published:31 Jan 2020
    6.8
    Medium

    CVE-2014-3866

    Last Modified: 8 Jan 2016

    Multiple cross-site request forgery (CSRF) vulnerabilities in user_settings.php in Usercake 2.0.2 and earlier allow remote attackers to hijack the authentication of administrators for requests that change the (1) administrative password via the passwordc parameter or (2) administrative e-mail address via the email parameter.

    Source:Dolev Farhi
    Published:26 May 2014
    6.4
    Medium

    CVE-2014-3865

    Last Modified: 10 Jan 2016

    Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunction with (1) missing --- and +++ header lines or (2) a +++ header line with a blank pathname.

    Source:Raphael Geissert
    Published:30 May 2014
    6.5
    Medium

    CVE-2014-3857

    Last Modified: 2 Jul 2014

    Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) x_16 or (2) x_17 parameter to print.php.

    Source:Khashayar Fereidani
    Published:3 Jul 2014
    6.8
    Medium

    CVE-2014-3854

    Last Modified: 8 Jan 2016

    Cross-site request forgery (CSRF) vulnerability in admin/addScript.py in Pyplate 0.08 allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the title parameter.

    Source:Henri Salo
    Published:7 Aug 2014
    4.3
    Medium

    CVE-2014-3849

    Last Modified: 28 Apr 2014

    The iMember360 plugin 3.8.012 through 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to delete arbitrary users via a request containing a user name in the Email parameter and the API key in the i4w_clearuser parameter.

    Source:Everett Griffiths
    Published:23 May 2014
    5
    Medium

    CVE-2014-3848

    Last Modified: 28 Apr 2014

    The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials via the i4w_dbinfo parameter.

    Source:Everett Griffiths
    Published:23 May 2014
    4.3
    Medium

    CVE-2014-3842

    Last Modified: 28 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the iMember360 plugin 3.8.012 through 3.9.001 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) decrypt or (2) encrypt parameter.

    Source:Everett Griffiths
    Published:22 May 2014
    3.5
    Low

    CVE-2014-3840

    Last Modified: 29 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web script or HTML via a (1) tag or the (2) title of a source in a Staging folder, (3) Name field in a bootstrap setup, or Title field in a (4) smart link or (5) web form.

    Source:Dolev Farhi
    Published:27 May 2014
    10
    Critical

    CVE-2014-3829

    Last Modified: 23 Mar 2017

    displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.

    Source:Metasploit
    Published:23 Oct 2014
    10
    Critical

    CVE-2014-3828

    Last Modified: 23 Mar 2017

    Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.php, (2) the sid parameter to views/graphs/GetXmlTree.php, (3) the session_id parameter to views/graphs/graphStatus/displayServiceStatus.php, (4) the mnftr_id parameter to configuration/configObject/traps/GetXMLTrapsForVendor.php, or (5) the index parameter to common/javascript/commandGetArgs/cmdGetExample.php in include/.

    Source:Metasploit
    Published:23 Oct 2014
    5
    Medium

    CVE-2014-3806

    Last Modified: 12 May 2014

    Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the xml_path parameter.

    Source:Jamal Pecou
    Published:21 May 2014
    10
    Critical

    CVE-2014-3805

    Last Modified: 16 Dec 2016

    The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) get_license, (2) get_log_line, or (3) update_system/upgrade_pro_web request, a different vulnerability than CVE-2014-3804.

    Source:Alfredo Ramirez
    Published:13 Jun 2014
    10
    Critical

    CVE-2014-3804

    Last Modified: 16 Dec 2016

    The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) update_system_info_debian_package, (2) ossec_task, (3) set_ossim_setup admin_ip, (4) sync_rserver, or (5) set_ossim_setup framework_ip request, a different vulnerability than CVE-2014-3805.

    Source:Metasploit
    Published:13 Jun 2014
    6.8
    Medium

    CVE-2014-3792

    Last Modified: 30 Apr 2014

    Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the uiViewTools_Password and uiViewTools_PasswordConfirm parameters to Forms/tools_admin_1.

    Source:shyamkumar somana
    Published:20 May 2014
    10
    Critical

    CVE-2014-3791

    Last Modified: 24 May 2014

    Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.ghp.

    Source:superkojiman
    Published:20 May 2014
    7.5
    High

    CVE-2014-3789

    Last Modified: 25 Jun 2014

    GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vectors.

    Source:Metasploit
    Published:22 May 2014
    6.8
    Medium

    CVE-2014-3778

    Last Modified: 18 Jun 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in goform/RgDdns in ARRIS (formerly Motorola) SBG901 SURFboard Wireless Cable Modem allow remote attackers to hijack the authentication of administrators for requests that (1) change the dns service via the DdnsService parameter, (2) change the username via the DdnsUserName parameter, (3) change the password via the DdnsPassword parameter, or (4) change the host name via the DdnsHostName parameter.

    Source:Blessen Thomas
    Published:19 Jun 2014
    7.5
    High

    CVE-2014-3757

    Last Modified: 22 Apr 2014

    SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attackers to execute arbitrary SQL commands via the sorter_value parameter.

    Source:chapp
    Published:15 May 2014
    7.5
    High

    CVE-2014-3749

    Last Modified: 7 Jan 2016

    SQL injection vulnerability in Construtiva CIS Manager allows remote attackers to execute arbitrary SQL commands via the email parameter to autenticar/lembrarlogin.asp.

    Source:Edge
    Published:20 May 2014
    3.5
    Low

    CVE-2014-3740

    Last Modified: 13 May 2014

    Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page.

    Source:Dolev Farhi
    Published:11 Sept 2014
    4.3
    Medium

    CVE-2014-3738

    Last Modified: 25 Jul 2014

    Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the title of a device.

    Source:Dolev Farhi
    Published:20 May 2014
    Unknown

    CVE-2014-3736

    https://www.exploit-db.com/exploits/39183

    7.5
    High

    CVE-2014-3704

    Last Modified: 29 Mar 2018

    The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

    Source:Claudio Viviani
    Published:16 Oct 2014
    Low

    CVE-2014-3671

    Last Modified: 25 Sept 2014

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187. Reason: This candidate is a duplicate of CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, and CVE-2014-7187. Notes: All CVE users should reference CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, and CVE-2014-7187 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Shaun Colley
    Published:13 Oct 2014
    Low

    CVE-2014-3659

    Last Modified: 25 Sept 2014

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-7169. Reason: This candidate is a reservation duplicate of CVE-2014-7169 because the CNA for this ID did not follow multiple procedures that are intended to minimize duplicate CVE assignments. Notes: All CVE users should reference CVE-2014-7169 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Shaun Colley
    Published:25 Sept 2014
    6.1
    Medium

    CVE-2014-3656

    Last Modified: 21 Nov 2024

    JBoss KeyCloak: XSS in login-status-iframe.html

    Published:21 Oct 2014
    7.5
    High

    CVE-2014-3651

    Last Modified: 20 Apr 2025

    JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/qrcode, related to QR code generation.

    Published:21 Oct 2014
    7.2
    High

    CVE-2014-3631

    Last Modified: 4 Mar 2015

    The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation.

    Source:Emeric Nasi
    Published:9 Sept 2014
    5
    Medium

    CVE-2014-3625

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

    Published:11 Nov 2014
    7.5
    High

    CVE-2014-3576

    Last Modified: 12 Apr 2025

    The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.

    Published:17 Jul 2015
    3.7
    Low

    CVE-2014-3570

    Last Modified: 12 Apr 2025

    The BN_sqr implementation in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not properly calculate the square of a BIGNUM value, which might make it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors, related to crypto/bn/asm/mips.pl, crypto/bn/asm/x86_64-gcc.c, and crypto/bn/bn_asm.c.

    Published:8 Jan 2015
    3.4
    Low

    CVE-2014-3566

    Last Modified: 28 May 2026

    The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

    Published:14 Oct 2014
    3.5
    Low

    CVE-2014-3551

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the advanced-grading implementation in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) qualification or (2) rating field in a rubric.

    Published:29 Jul 2014
    3.5
    Low

    CVE-2014-3544

    Last Modified: 27 Jul 2014

    Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to inject arbitrary web script or HTML via the Skype ID profile field.

    Source:Osanda Malith Jayathissa
    Published:29 Jul 2014
    5
    Medium

    CVE-2014-3507

    Last Modified: 12 Apr 2025

    Memory leak in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory consumption) via zero-length DTLS fragments that trigger improper handling of the return value of a certain insert function.

    Published:6 Aug 2014
    5
    Medium

    CVE-2014-3488

    Last Modified: 12 Apr 2025

    The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

    Published:11 Jun 2014
    6.8
    Medium

    CVE-2014-3466

    Last Modified: 12 Apr 2025

    Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.

    Published:30 May 2014
    9.3
    Critical

    CVE-2014-3444

    Last Modified: 6 Jan 2016

    The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.

    Source:Aryan Bayaninejad
    Published:20 May 2014
    4.3
    Medium

    CVE-2014-3443

    Last Modified: 13 May 2014

    JetMPAd.ax in JetAudio 8.1.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file.

    Source:Aryan Bayaninejad
    Published:14 May 2014
    4.3
    Medium

    CVE-2014-3442

    Last Modified: 6 Jan 2016

    Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malformed .FLV file, related to f263.w5s.

    Source:Aryan Bayaninejad
    Published:23 May 2014
    4.3
    Medium

    CVE-2014-3441

    Last Modified: 15 Nov 2016

    codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as demonstrated by a png in a .wave file.

    Source:Aryan Bayaninejad
    Published:14 May 2014
    6.1
    Medium

    CVE-2014-3439

    Last Modified: 6 Nov 2014

    ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors.

    Source:SEC Consult
    Published:7 Nov 2014
    4.3
    Medium

    CVE-2014-3438

    Last Modified: 6 Nov 2014

    Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:SEC Consult
    Published:7 Nov 2014
    7.5
    High

    CVE-2014-3437

    Last Modified: 6 Nov 2014

    The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Source:SEC Consult
    Published:7 Nov 2014
    6.9
    Medium

    CVE-2014-3434

    Last Modified: 3 Dec 2016

    Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL call.

    Source:ryujin & sickness
    Published:6 Aug 2014
    5
    Medium

    CVE-2014-3427

    Last Modified: 27 Jan 2016

    CRLF injection vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the model parameter to servlet.

    Source:Jesus Oquendo
    Published:16 Jul 2014
    10
    Critical

    CVE-2014-3418

    Last Modified: 10 Jul 2014

    config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the skipjackUsername parameter.

    Source:Nate Kettlewell
    Published:15 Jul 2014
    6.5
    Medium

    CVE-2014-3415

    Last Modified: 28 May 2014

    SQL injection vulnerability in Sharetronix before 3.4 allows remote authenticated users to execute arbitrary SQL commands via the invite_users[] parameter to the /invite page for a group.

    Source:High-Tech Bridge SA
    Published:29 May 2014