9.3
    Critical

    CVE-2014-2782

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:19 Jun 2014
    7.5
    High

    CVE-2014-2777

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-1778.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2776

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, and CVE-2014-2772.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2775

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, and CVE-2014-2766.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2773

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2768.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2772

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, and CVE-2014-2776.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2771

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, and CVE-2014-2769.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2770

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1781, CVE-2014-1792, and CVE-2014-1804.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2769

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, and CVE-2014-2771.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2768

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-2773.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2767

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2766

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2765

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2764

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2769, and CVE-2014-2771.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2763

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2761

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2772, and CVE-2014-2776.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2760

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2759

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2758

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2757

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, and CVE-2014-1803.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2756

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2755

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2754

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1774 and CVE-2014-1788.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-2753

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-1785, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    5.8
    Medium

    CVE-2014-2734

    Last Modified: 12 Apr 2025

    The openssl extension in Ruby 2.x does not properly maintain the state of process memory after a file is reopened, which allows remote attackers to spoof signatures within the context of a Ruby script that attempts signature verification after performing a certain sequence of filesystem operations. NOTE: this issue has been disputed by the Ruby OpenSSL team and third parties, who state that the original demonstration PoC contains errors and redundant or unnecessarily-complex code that does not appear to be related to a demonstration of the issue. As of 20140502, CVE is not aware of any public comment by the original researcher

    Published:10 Apr 2014
    7.5
    High

    CVE-2014-2674

    Last Modified: 31 Mar 2014

    Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the loop parameter in an ajax_navigation action to wp-admin/admin-ajax.php.

    Source:Glyn Wintle
    Published:19 Mar 2018
    6.8
    Medium

    CVE-2014-2671

    Last Modified: 24 Mar 2014

    Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted WAV file.

    Source:TUNISIAN CYBER
    Published:30 Mar 2014
    5
    Medium

    CVE-2014-2668

    Last Modified: 24 Sept 2018

    Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids.

    Source:Krusty Hack
    Published:28 Mar 2014
    4.3
    Medium

    CVE-2014-2647

    Last Modified: 27 Oct 2014

    Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communications Broker) before 11.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Matt Schmidt
    Published:19 Oct 2014
    4.4
    Medium

    CVE-2014-2630

    Last Modified: 5 Feb 2020

    Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via unknown vectors.

    Source:redtimmysec
    Published:12 Aug 2014
    10
    Critical

    CVE-2014-2624

    Last Modified: 2 Oct 2014

    Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2264.

    Source:Metasploit
    Published:11 Sept 2014
    10
    Critical

    CVE-2014-2623

    Last Modified: 10 Oct 2016

    Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.

    Source:Juttikhun Khamchaiyaphum
    Published:18 Jul 2014
    4
    Medium

    CVE-2014-2612

    Last Modified: 2 Nov 2017

    Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sensitive information via unknown vectors.

    Source:Brandon Perry
    Published:28 Jun 2014
    6.8
    Medium

    CVE-2014-2598

    Last Modified: 14 Apr 2014

    Cross-site request forgery (CSRF) vulnerability in the Quick Page/Post Redirect plugin before 5.0.5 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the quickppr_redirects[request][] parameter in the redirect-updates page to wp-admin/admin.php.

    Source:Tom Adams
    Published:5 Jan 2015
    9.8
    Critical

    CVE-2014-2595

    Last Modified: 21 Jan 2016

    Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.

    Source:Nick Hayes
    Published:12 Feb 2020
    4
    Medium

    CVE-2014-2588

    Last Modified: 19 Mar 2014

    Directory traversal vulnerability in servlet/downloadReport in McAfee Asset Manager 6.6 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the reportFileName parameter.

    Source:Brandon Perry
    Published:23 Mar 2014
    6.5
    Medium

    CVE-2014-2587

    Last Modified: 19 Mar 2014

    SQL injection vulnerability in jsp/reports/ReportsAudit.jsp in McAfee Asset Manager 6.6 allows remote authenticated users to execute arbitrary SQL commands via the username of an audit report (aka user parameter).

    Source:Brandon Perry
    Published:23 Mar 2014
    4.3
    Medium

    CVE-2014-2586

    Last Modified: 19 Mar 2014

    Cross-site scripting (XSS) vulnerability in the login audit form in McAfee Cloud Single Sign On (SSO) allows remote attackers to inject arbitrary web script or HTML via a crafted password.

    Source:Brandon Perry
    Published:23 Mar 2014
    7.6
    High

    CVE-2014-2579

    Last Modified: 10 Apr 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password via the config task to index2.php or (2) when the enable_db_backup and sql_mem options are enabled, access the database backup functionality via the dbbackup_comp parameter in the generate action to index2.php. NOTE: vector 2 might be a duplicate of CVE-2014-2340, which is for the XCloner Wordpress plugin. NOTE: remote attackers can leverage CVE-2014-2996 with vector 2 to execute arbitrary commands.

    Source:High-Tech Bridge SA
    Published:25 Apr 2014
    6.5
    Medium

    CVE-2014-2575

    Last Modified: 9 Jun 2014

    Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.

    Source:RedTeam Pentesting
    Published:6 Jun 2014
    7.5
    High

    CVE-2014-2560

    Last Modified: 1 Apr 2014

    The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.

    Source:Jason Ostrom
    Published:12 Feb 2020
    6.8
    Medium

    CVE-2014-2559

    Last Modified: 14 Apr 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that change unspecified plugin options via a request to wp-admin/options-general.php.

    Source:Tom Adams
    Published:17 Oct 2014
    7.5
    High

    CVE-2014-2540

    Last Modified: 10 Apr 2014

    SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the site_directory_sort_field parameter to guest/site_directory.

    Source:High-Tech Bridge SA
    Published:11 Apr 2014
    4.9
    Medium

    CVE-2014-2534

    Last Modified: 13 Mar 2014

    /sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow.

    Source:cenobyte
    Published:18 Mar 2014
    7.2
    High

    CVE-2014-2533

    Last Modified: 9 Oct 2018

    /sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument.

    Source:Metasploit
    Published:18 Mar 2014
    6.5
    Medium

    CVE-2014-2531

    Last Modified: 26 Mar 2014

    SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) Resellers interface, as demonstrated by the "or" key in a pgn8state object in an i object in a JSON object.

    Source:Eric Flokstra
    Published:21 Oct 2014
    3.6
    Low

    CVE-2014-2477

    Last Modified: 27 Oct 2016

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.26, 4.1.34, 4.2.26, and 4.3.12 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-2486.

    Source:Metasploit
    Published:17 Jul 2014
    4
    Medium

    CVE-2014-2424

    Last Modified: 7 Jul 2014

    Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system.

    Source:Metasploit
    Published:16 Apr 2014
    4.3
    Medium

    CVE-2014-2399

    Last Modified: 27 Jun 2014

    Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.

    Source:RedTeam Pentesting
    Published:16 Apr 2014
    6.8
    Medium

    CVE-2014-2383

    Last Modified: 10 Oct 2016

    dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.

    Source:Portcullis
    Published:28 Apr 2014