Latest CVE Feed
-
10.0
HIGHCVE-2014-9954
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36388559.... Read more
Affected Products : android- EPSS Score: %0.58
- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-9953
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714770.... Read more
Affected Products : android- EPSS Score: %0.58
- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9919
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the fullname parameter to signup.php.... Read more
Affected Products : bilboplanet- EPSS Score: %0.21
- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9918
An issue was discovered in Bilboplanet 2.0. Stored XSS exists in the user_id parameter to signup.php.... Read more
Affected Products : bilboplanet- EPSS Score: %0.21
- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9917
An issue was discovered in Bilboplanet 2.0. There is a stored XSS vulnerability when adding a tag via the user/?page=tribes tags parameter.... Read more
Affected Products : bilboplanet- EPSS Score: %0.21
- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-9908
A Denial of Service vulnerability exists in Google Android 4.4.4, 5.0.2, and 5.1.1, which allows malicious users to block Bluetooh access (Android Bug ID A-28672558).... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9753
confirm.php in ATutor 2.2 and earlier allows remote attackers to bypass authentication and gain access as an existing user via the auto_login parameter.... Read more
Affected Products : atutor- EPSS Score: %1.68
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2014-9748
The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the locks of other threads, which allows attackers to cause a denial of service (deadlock) or possibly have unspe... Read more
- EPSS Score: %0.40
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-9720
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.... Read more
Affected Products : tornado- EPSS Score: %0.90
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-9702
system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers to obtain sensitive information (username and password) via any request, such as a password reset request.... Read more
Affected Products : cmfive- EPSS Score: %0.34
- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-9699
The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs, design files (i.e., a history of print files), and more are exposed to unauthenticated attackers through this HTTP server.... Read more
- EPSS Score: %0.51
- Published: Jun. 24, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9630
The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (me... Read more
Affected Products : vlc_media_player- EPSS Score: %0.56
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9629
Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.... Read more
Affected Products : vlc_media_player- EPSS Score: %4.50
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9628
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a b... Read more
Affected Products : vlc_media_player- EPSS Score: %1.63
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9627
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly ... Read more
Affected Products : vlc_media_player- EPSS Score: %0.34
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9626
Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7.... Read more
Affected Products : vlc_media_player- EPSS Score: %0.47
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9625
The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execu... Read more
Affected Products : vlc_media_player- EPSS Score: %4.22
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9617
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.... Read more
Affected Products : netsweeper- EPSS Score: %26.19
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9615
Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter to webadmin/deny/index.php.... Read more
Affected Products : netsweeper- EPSS Score: %9.36
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9614
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.... Read more
Affected Products : netsweeper- EPSS Score: %69.54
- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024