Latest CVE Feed
-
4.3
MEDIUMCVE-2014-3470
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference an... Read more
Affected Products : enterprise_linux fedora leap mariadb openssl opensuse linux_enterprise_server linux_enterprise_desktop linux_enterprise_software_development_kit storage +1 more products- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4217
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, and 12.1.1.0 allows remote attackers to affect integrity via vectors related to WLS - Web Services.... Read more
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9031
Cross-site scripting (XSS) vulnerability in the wptexturize function in WordPress before 3.7.5, 3.8.x before 3.8.5, and 3.9.x before 3.9.3 allows remote attackers to inject arbitrary web script or HTML via crafted use of shortcode brackets in a text field... Read more
Affected Products : wordpress- Published: Nov. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9032
Cross-site scripting (XSS) vulnerability in the media-playlists feature in WordPress before 3.9.x before 3.9.3 and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : wordpress- Published: Nov. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9036
Cross-site scripting (XSS) vulnerability in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted Cascading Style Sheets (CSS) token sequence in a ... Read more
- Published: Nov. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2024-30217
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting the ... Read more
Affected Products :- Published: Apr. 09, 2024
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2014-6171
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script o... Read more
Affected Products : websphere_portal- Published: Dec. 19, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7203
libzmq (aka ZeroMQ/C++) 4.0.x before 4.0.5 does not ensure that nonces are unique, which allows man-in-the-middle attackers to conduct replay attacks via unspecified vectors.... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8091
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to caus... Read more
- Published: Dec. 10, 2014
- Modified: Aug. 29, 2025
-
4.3
MEDIUMCVE-2014-9035
Cross-site scripting (XSS) vulnerability in Press This in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Nov. 25, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9059
lib/setup.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide charset information in HTTP headers, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 charact... Read more
Affected Products : moodle- Published: Nov. 24, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9094
Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand param... Read more
Affected Products : video_gallery- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6176
IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and uncondi... Read more
Affected Products : business_process_manager websphere_enterprise_service_bus websphere_process_server- Published: Dec. 16, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9103
Multiple cross-site scripting (XSS) vulnerabilities in the Kunena component before 3.0.6 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) index value of an array parameter or the filename parameter in the Content-Dispo... Read more
Affected Products : kunena- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7258
Cross-site scripting (XSS) vulnerability in KENT-WEB Clip Board 2.91 and earlier, when running certain versions of Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : clip_board- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6167
Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL... Read more
Affected Products : websphere_application_server- Published: Dec. 18, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2008-5240
xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input value to determine the memory allocation and does not check the result for (1) the MATROSKA_ID_TR_CODECPRIVATE track entry element processed by demux_matroska.c; and (2) ... Read more
Affected Products : xine-lib- Published: Nov. 26, 2008
- Modified: Apr. 09, 2025
-
4.3
MEDIUMCVE-2014-9100
Cross-site scripting (XSS) vulnerability in the WhyDoWork AdSense plugin 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the idcode parameter in the whydowork_adsense page to wp-admin/options-general.php.... Read more
Affected Products : whydowork_adsense- Published: Nov. 26, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8150
CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.... Read more
- Published: Jan. 15, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6137
Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : tivoli_endpoint_manager- Published: Feb. 16, 2015
- Modified: Apr. 12, 2025