Latest CVE Feed
-
5.9
MEDIUMCVE-2014-4024
SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 11.5.0 before HF5, and 11.5.1 before HF5, when used with third-party Secure Sockets Layer (SSL) accelerator... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager big-ip_edge_gateway +3 more products- Published: Mar. 19, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-4019
ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows remote attackers to read backup files via a direct request for rom-0.... Read more
- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2014-3999
The Horde_Ldap library before 2.0.6 for Horde allows remote attackers to bypass authentication by leveraging knowledge of the LDAP bind user DN.... Read more
Affected Products : horde_ldap- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3990
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a cr... Read more
Affected Products : opencart- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-3979
Bytemark Symbiosis allows remote attackers to cause a denial of service via a crafted username, which triggers the firewall to blacklist the IP.... Read more
Affected Products : symbiosis- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-3972
Directory traversal vulnerability in Apexis APM-J601-WS cameras with firmware before 17.35.2.49 allows remote attackers to read arbitrary files via unspecified vectors.... Read more
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2014-3919
A vulnerability exists in Netgear CG3100 devices before 3.9.2421.13.mp3 V0027 via an embed malicious script in an unspecified page, which could let a malicious user obtain sensitive information.... Read more
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3879
OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass auth... Read more
Affected Products : freebsd- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3875
The addto parameter to fup in Frams' Fast File EXchange (F*EX, aka fex) before fex-2014053 allows remote attackers to conduct cross-site scripting (XSS) attacks... Read more
Affected Products : fex- Published: Nov. 27, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-3868
Multiple SQL injection vulnerabilities in ZeusCart 4.x.... Read more
Affected Products : zeuscart- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-3860
Xilisoft Video Converter Ultimate 7.8.1 build-20140505 has a DLL Hijacking vulnerability... Read more
Affected Products : video_converter- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2014-3856
The funced function in fish (aka fish-shell) 1.23.0 before 2.1.1 does not properly create temporary files, which allows local users to gain privileges via a temporary file with a predictable name.... Read more
Affected Products : fish- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-3827
Multiple cross-site scripting (XSS) vulnerabilities in the MyBB (aka MyBulletinBoard) before 1.8.4 allow remote authenticated users to inject arbitrary web script or HTML via the title parameter in the (1) edit or (2) add action in the user-users module o... Read more
Affected Products : mybb- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-3826
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.13 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in the edit action of the config-profile_fields module.... Read more
Affected Products : mybb- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3809
Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.... Read more
- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2014-3798
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.... Read more
Affected Products : xenserver- Published: Jul. 11, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-3753
AgileBits 1Password through 1.0.9.340 allows security feature bypass... Read more
Affected Products : 1password- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2014-3752
The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights to execute arbitrary code with SYSTEM privileges via a crafted 0x83170180 call.... Read more
Affected Products : totalprotection- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3743
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.... Read more
Affected Products : marked- Published: Jan. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3719
Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to execute arbitrary SQL commands via the (1) find, (2) lib, or (3) sid parameter.... Read more
Affected Products : aleph_500- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024