Latest CVE Feed
-
5.0
MEDIUMCVE-2014-9601
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.... Read more
- EPSS Score: %1.08
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-9496
The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.... Read more
- EPSS Score: %0.12
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9480
Cross-site scripting (XSS) vulnerability in the Hovercards extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via vectors related to text extracts.... Read more
Affected Products : mediawiki- EPSS Score: %0.28
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9479
Cross-site scripting (XSS) vulnerability in the preview in the TemplateSandbox extension for MediaWiki allows remote attackers to inject arbitrary web script or HTML via the text parameter to Special:TemplateSandbox.... Read more
Affected Products : mediawiki- EPSS Score: %0.28
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-9478
Cross-site scripting (XSS) vulnerability in the preview in the ExpandTemplates extension for MediaWiki, when $wgRawHTML is set to true, allows remote attackers to inject arbitrary web script or HTML via the wpInput parameter to the Special:ExpandTemplates... Read more
Affected Products : mediawiki- EPSS Score: %0.28
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9477
Multiple cross-site scripting (XSS) vulnerabilities in the Listings extension for MediaWiki allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) url parameter.... Read more
Affected Products : mediawiki- EPSS Score: %0.28
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9476
MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedi... Read more
Affected Products : mediawiki- EPSS Score: %0.93
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-9475
Cross-site scripting (XSS) vulnerability in thumb.php in MediaWiki before 1.19.23, 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote authenticated users to inject arbitrary web script or HTML via a wikitext message.... Read more
Affected Products : mediawiki- EPSS Score: %0.21
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9471
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command.... Read more
- EPSS Score: %2.61
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-7814
SQL injection vulnerability in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 allows remote authenticated users to execute arbitrary SQL commands via a crafted REST API request to an SQL filter.... Read more
Affected Products : cloudforms_3.1_management_engine- EPSS Score: %0.31
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-6386
Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47-D10, 12.2 before 12.2R9, 12.3R2 before 12.3R2-S3, 12.3 before 12.3R3, 13.1 before 13.1R4, and 13.2 before 13.2R1 a... Read more
- EPSS Score: %0.69
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2014-6385
Juniper Junos 11.4 before 11.4R13, 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D15, 12.2 before 12.2R9, 12.3R7 before 12.3R7-S1, 12.3 before 12.3R8, 13.1 before 13.1R5, 13.2 before 13.2R6, 13.3 before 13.3R4, 14.1 before... Read more
- EPSS Score: %0.38
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-6384
Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 before 13.2R6, 13.3 before 13.3R5, 14.1 before 14.1R3, and 14.2 before 14.2R1 does not properly handle double... Read more
- EPSS Score: %0.05
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-6383
The stateless firewall in Juniper Junos 13.3R3, 14.1R1, and 14.1R2, when using Trio-based PFE modules, does not properly match ports, which might allow remote attackers to bypass firewall rule.... Read more
- EPSS Score: %0.45
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2014-6382
The Juniper MX Series routers with Junos 13.3R3 through 13.3Rx before 13.3R6, 14.1 before 14.1R4, 14.1X50 before 14.1X50-D70, and 14.2 before 14.2R2, when configured as a broadband edge (BBE) router, allows remote attackers to cause a denial of service (j... Read more
- EPSS Score: %0.46
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-3692
The customization template in Red Hat CloudForms 3.1 Management Engine (CFME) 5.3 uses a default password for the root account when a password is not specified for a new image, which allows remote attackers to gain privileges.... Read more
Affected Products : cloudforms_3.1_management_engine- EPSS Score: %1.70
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-1949
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.... Read more
- EPSS Score: %0.04
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2015-1060
Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header.... Read more
- EPSS Score: %7.76
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-1059
Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in /app/webroot/upload... Read more
- EPSS Score: %3.77
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-1058
Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data[Category][title] parameter to admin/categories/add, (2) data[Field][title] parameter to admin/fields/ajax_... Read more
- EPSS Score: %10.84
- Published: Jan. 16, 2015
- Modified: Apr. 12, 2025