Latest CVE Feed
-
6.5
MEDIUMCVE-2014-9720
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.... Read more
Affected Products : tornado- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-9702
system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers to obtain sensitive information (username and password) via any request, such as a password reset request.... Read more
Affected Products : cmfive- Published: Jun. 01, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-9699
The MakerBot Replicator 5G printer runs an Apache HTTP Server with directory indexing enabled. Apache logs, system logs, design files (i.e., a history of print files), and more are exposed to unauthenticated attackers through this HTTP server.... Read more
- Published: Jun. 24, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9630
The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (me... Read more
Affected Products : vlc_media_player- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9629
Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.... Read more
Affected Products : vlc_media_player- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9628
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a b... Read more
Affected Products : vlc_media_player- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9627
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly ... Read more
Affected Products : vlc_media_player- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9626
Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7.... Read more
Affected Products : vlc_media_player- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-9625
The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execu... Read more
Affected Products : vlc_media_player- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9617
Open redirect vulnerability in remotereporter/load_logfiles.php in Netsweeper before 4.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.... Read more
Affected Products : netsweeper- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9615
Cross-site scripting (XSS) vulnerability in Netsweeper 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter to webadmin/deny/index.php.... Read more
Affected Products : netsweeper- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9614
The Web Panel in Netsweeper before 4.0.5 has a default password of branding for the branding account, which makes it easier for remote attackers to obtain access via a request to webadmin/.... Read more
Affected Products : netsweeper- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9613
Multiple SQL injection vulnerabilities in Netsweeper before 2.6.29.10 allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to webadmin/auth/verification.php or (2) dpid parameter to webadmin/deny/index.php.... Read more
Affected Products : netsweeper- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9612
SQL injection vulnerability in remotereporter/load_logfiles.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to execute arbitrary SQL commands via the server parameter.... Read more
Affected Products : netsweeper- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-9609
Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action... Read more
Affected Products : netsweeper- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9608
Cross-site scripting (XSS) vulnerability in webadmin/policy/group_table_ajax.php/ in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.... Read more
Affected Products : netsweeper- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9607
Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter.... Read more
Affected Products : netsweeper- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-9606
Multiple cross-site scripting (XSS) vulnerabilities in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) server parameter to remotereporter/load_logfiles.php, (2)... Read more
Affected Products : netsweeper- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2014-9563
CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allows remote authenticated users to modify the root password and consequently access th... Read more
- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9530
A vulnerability exists in nw.js before 0.11.3 when calling nw methods from normal frames, which has an unspecified impact.... Read more
Affected Products : nw- Published: Feb. 07, 2020
- Modified: Nov. 21, 2024