5
    Medium

    CVE-2014-1908

    Last Modified: 28 Feb 2014

    The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

    Source:High-Tech Bridge SA
    Published:29 Dec 2014
    6.4
    Medium

    CVE-2014-1907

    Last Modified: 28 Feb 2014

    Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logout.php.

    Source:High-Tech Bridge SA
    Published:6 Mar 2014
    4.3
    Medium

    CVE-2014-1906

    Last Modified: 28 Feb 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) m parameter to lb_status.php; (2) msg parameter to vc_chatlog.php; n parameter to (3) channel.php, (4) htmlchat.php, (5) video.php, or (6) videotext.php; (7) message parameter to lb_logout.php; or ct parameter to (8) lb_status.php or (9) v_status.php in ls/.

    Source:High-Tech Bridge SA
    Published:6 Mar 2014
    10
    Critical

    CVE-2014-1905

    Last Modified: 28 Feb 2014

    Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, and then accessing the file via a direct request to a wp-content/plugins/videowhisper-live-streaming-integration/ls/snapshots/ pathname, as demonstrated by a .php.jpg filename.

    Source:High-Tech Bridge SA
    Published:29 Dec 2014
    7.5
    High

    CVE-2014-1903

    Last Modified: 12 Apr 2018

    admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not restrict the set of functions accessible to the API handler, which allows remote attackers to execute arbitrary PHP code via the function and args parameters to admin/config.php.

    Source:@0x00string
    Published:18 Feb 2014
    6.5
    Medium

    CVE-2014-1889

    Last Modified: 16 Feb 2014

    The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.

    Source:Pietro Oliva
    Published:10 Apr 2018
    7.5
    High

    CVE-2014-1854

    Last Modified: 23 Feb 2014

    SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free plugin 3.9 through 3.9.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the track parameter.

    Source:High-Tech Bridge SA
    Published:27 Feb 2014
    10
    Critical

    CVE-2014-1849

    Last Modified: 8 Jan 2016

    Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifying arbitrary camera records in the Foscam DNS server.

    Source:Sergey Shekyan
    Published:14 May 2014
    5
    Medium

    CVE-2014-1843

    Last Modified: 11 Feb 2014

    Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to obtain the property information of an arbitrary home folder via a Properties action with a .. (dot dot) in the src parameter.

    Source:Fara Rustein
    Published:29 Apr 2014
    5
    Medium

    CVE-2014-1842

    Last Modified: 11 Feb 2014

    Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to list all usernames via a Go action with a .. (dot dot) in the search-bar value.

    Source:Fara Rustein
    Published:29 Apr 2014
    5
    Medium

    CVE-2014-1841

    Last Modified: 11 Feb 2014

    Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's home folder via a Move action with a .. (dot dot) in the src parameter.

    Source:Fara Rustein
    Published:29 Apr 2014
    6.4
    Medium

    CVE-2014-1836

    Last Modified: 25 Jan 2018

    Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.

    Source:Pedro Ribeiro
    Published:1 Jul 2015
    9.3
    Critical

    CVE-2014-1815

    Last Modified: 28 Aug 2014

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as exploited in the wild in May 2014, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0310.

    Source:PhysicalDrive0
    Published:14 May 2014
    8.8
    High

    CVE-2014-1812

    Last Modified: 22 Apr 2026

    The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka "Group Policy Preferences Password Elevation of Privilege Vulnerability."

    Published:14 May 2014
    10
    Critical

    CVE-2014-1806

    Last Modified: 17 Nov 2014

    The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFilterLevel Vulnerability."

    Source:James Forshaw
    Published:14 May 2014
    9.3
    Critical

    CVE-2014-1805

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1804

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1781, CVE-2014-1792, and CVE-2014-2770.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1803

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1799, and CVE-2014-2757.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1802

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1800

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1799

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1779, CVE-2014-1803, and CVE-2014-2757.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1797

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1794, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1796

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 6 and 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1795

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1794

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1780, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1792

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1781, CVE-2014-1804, and CVE-2014-2770.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1791

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1790

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1789.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1789

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1790.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1788

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1774 and CVE-2014-2754.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1786

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1784, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1785

    Last Modified: 22 Dec 2016

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1782, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.

    Source:Skylined
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1784

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1783, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1783

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1773, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1782

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1781

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1792, CVE-2014-1804, and CVE-2014-2770.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1780

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1772, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1779

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1775, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    6.8
    Medium

    CVE-2014-1778

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    4.3
    Medium

    CVE-2014-1777

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to read local files on the client via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1775

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0282, CVE-2014-1779, CVE-2014-1799, CVE-2014-1803, and CVE-2014-2757.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1774

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1788 and CVE-2014-2754.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1773

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1783, CVE-2014-1784, CVE-2014-1786, CVE-2014-1795, CVE-2014-1805, CVE-2014-2758, CVE-2014-2759, CVE-2014-2765, CVE-2014-2766, and CVE-2014-2775.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1772

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1780, CVE-2014-1794, CVE-2014-1797, CVE-2014-1802, CVE-2014-2756, CVE-2014-2763, CVE-2014-2764, CVE-2014-2769, and CVE-2014-2771.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    6.8
    Medium

    CVE-2014-1771

    Last Modified: 22 Jul 2014

    SChannel in Microsoft Internet Explorer 6 through 11 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to obtain sensitive information or modify TLS session data via a "triple handshake attack," aka "TLS Server Certificate Renegotiation Vulnerability."

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    9.3
    Critical

    CVE-2014-1770

    Last Modified: 22 Jul 2014

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::CreateInitialMarkup function.

    Source:Drozdova Liudmila
    Published:22 May 2014
    9.3
    Critical

    CVE-2014-1769

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1782, CVE-2014-1785, CVE-2014-2753, CVE-2014-2755, CVE-2014-2760, CVE-2014-2761, CVE-2014-2772, and CVE-2014-2776.

    Source:Drozdova Liudmila
    Published:11 Jun 2014
    7.2
    High

    CVE-2014-1767

    Last Modified: 31 Jan 2017

    Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

    Source:Rick Larabee
    Published:8 Jul 2014
    9.3
    Critical

    CVE-2014-1766

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWest 2014. NOTE: the original disclosure referred to triggering a kernel bug with the Internet Explorer exploit payload, but this ID is not for a kernel vulnerability.

    Source:Drozdova Liudmila
    Published:27 Apr 2014
    10
    Critical

    CVE-2014-1764

    Last Modified: 22 Jul 2014

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.

    Source:Drozdova Liudmila
    Published:27 Apr 2014