Latest CVE Feed
-
5.5
MEDIUMCVE-2014-2079
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.... Read more
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-2078
The backend in Open-Xchange (OX) AppSuite 7.4.2 before 7.4.2-rev9 allows remote attackers to obtain sensitive information about user email addresses in opportunistic circumstances by leveraging a failure in e-mail auto configuration for external accounts.... Read more
Affected Products : open-xchange_appsuite- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-2073
Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "CATV5_Backbone_Bus."... Read more
Affected Products : catia- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-2072
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks... Read more
Affected Products : catia- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2014-2071
Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain privileges by advert... Read more
Affected Products : clearpass- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-2069
Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx.... Read more
Affected Products : eshtery_cms- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-2048
The user_openid app in ownCloud Server before 5.0.15 allows remote attackers to obtain access by leveraging an insecure OpenID implementation.... Read more
Affected Products : owncloud- Published: Mar. 26, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-2032
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwoo... Read more
- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2014-2031
Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of service (out-of-bounds read and crash) by leveraging permission to perform recursive queries against Deadwoo... Read more
- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-2030
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld stri... Read more
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-2025
Unrestricted file upload vulnerability in an unspecified third party tool in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to execute arbitrary code by uploading a file with an... Read more
Affected Products : intrexx- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2014-2017
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4.8.4, Enterprise Edition before 5.0.11 and 5.1.x before 5.1.4, and Community Edition before 4.7.11 and 4.8.x before 4.8.4 allows remote attackers to inject arb... Read more
Affected Products : eshop- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-1958
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.... Read more
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2014-1947
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involv... Read more
- Published: Feb. 17, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2014-1946
OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.... Read more
Affected Products : opendocman- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2014-1938
python-rply before 0.7.4 insecurely creates temporary files.... Read more
Affected Products : rply- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2014-1937
Gamera before 3.4.1 insecurely creates temporary files.... Read more
Affected Products : gamera- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGH- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2014-1935
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.... Read more
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-1925
SQL injection vulnerability in the MARC framework import/export function (admin/import_export_framework.pl) in Koha before 3.8.23, 3.10.x before 3.10.13, 3.12.x before 3.12.10, and 3.14.x before 3.14.3 allows remote authenticated users to execute arbitrar... Read more
Affected Products : koha- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024