Latest CVE Feed
-
6.5
MEDIUMCVE-2014-3798
The Windows Guest Tools in Citrix XenServer 6.2 SP1 and earlier allows remote attackers to cause a denial of service (guest OS crash) via a crafted Ethernet frame.... Read more
Affected Products : xenserver- Published: Jul. 11, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-3753
AgileBits 1Password through 1.0.9.340 allows security feature bypass... Read more
Affected Products : 1password- Published: Jan. 09, 2020
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2014-3752
The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights to execute arbitrary code with SYSTEM privileges via a crafted 0x83170180 call.... Read more
Affected Products : totalprotection- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3743
Multiple cross-site scripting (XSS) vulnerabilities in the Marked module before 0.3.1 for Node.js allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) gfm codeblocks (language) or (2) javascript url's.... Read more
Affected Products : marked- Published: Jan. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3719
Multiple SQL injection vulnerabilities in cgi-bin/review_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to execute arbitrary SQL commands via the (1) find, (2) lib, or (3) sid parameter.... Read more
Affected Products : aleph_500- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3718
Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/tag_m.cgi in Ex Libris ALEPH 500 (Integrated library management system) 18.1 and 20 allow remote attackers to inject arbitrary web script or HTML via the (1) find, (2) lib, or (3) sid paramete... Read more
Affected Products : aleph_500- Published: Jan. 30, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGH- Published: Dec. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3700
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data... Read more
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Dec. 15, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3656
JBoss KeyCloak: XSS in login-status-iframe.html... Read more
Affected Products : jboss_keycloak- Published: Dec. 10, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUM- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3652
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.... Read more
- Published: Dec. 15, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2014-3650
Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.... Read more
Affected Products : jboss_aerogear- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-3649
JBoss AeroGear has reflected XSS via the password field... Read more
Affected Products : jboss_aerogear- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-3648
The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is user controlled. If a bogus applications is registered with bad deviceTokens, one can generate endless except... Read more
Affected Products : jboss_aerogear- Published: Jul. 01, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-3643
jersey: XXE via parameter entities not disabled by the jersey SAX parser... Read more
Affected Products : jersey- Published: Dec. 15, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-3626
The Grails Resource Plugin often has to exchange URIs for resources with other internal components. Those other components will decode any URI passed to them. To protect against directory traversal the Grails Resource Plugin did the following: normalized ... Read more
Affected Products : resources- Published: Mar. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-3622
Use-after-free vulnerability in the add_post_var function in the Posthandler component in PHP 5.6.x before 5.6.1 might allow remote attackers to execute arbitrary code by leveraging a third-party filter extension that accesses a certain ksep value.... Read more
Affected Products : php- Published: Feb. 19, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-3607
DefaultHostnameVerifier in Ldaptive (formerly vt-ldap) does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers ... Read more
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-3603
The (1) HttpResource and (2) FileBackedHttpResource implementations in Shibboleth Identity Provider (IdP) before 2.4.1 and OpenSAML Java 2.6.2 do not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName... Read more
- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024