Latest CVE Feed
-
5.0
MEDIUMCVE-2014-8790
XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.... Read more
- Published: Jan. 20, 2015
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8625
Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or... Read more
Affected Products : dpkg- Published: Jan. 20, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8386
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file.... Read more
Affected Products : adamview- Published: Jan. 20, 2015
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2015-0973
Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.... Read more
- Published: Jan. 18, 2015
- Modified: Jun. 09, 2025
-
3.5
LOWCVE-2015-0862
Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as... Read more
Affected Products : rabbitmq_management- Published: Jan. 18, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2013-7252
kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.... Read more
Affected Products : kde_applications- Published: Jan. 18, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-0924
Ceragon FibeAir IP-10 bridges have a default password for the root account, which makes it easier for remote attackers to obtain access via a (1) HTTP, (2) SSH, (3) TELNET, or (4) CLI session.... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2015-0590
Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a meeting-join action, aka Bug ID CSCuo34165.... Read more
Affected Products : webex_meeting_center- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6197
IBM Security Network Protection 5.1.x and 5.2.x before 5.2.0.0 FP5 and 5.3.x before 5.3.0.0 FP1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-4835
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3032
Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3019
IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage-pool access via a TELNET session.... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-3018
IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to cause a denial of service (reboot) via a flood of IP packets.... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-9199
The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.... Read more
Affected Products : java_web_client- Published: Jan. 17, 2015
- Modified: Sep. 05, 2025
-
10.0
HIGHCVE-2014-9195
Phoenix Contact ProConOs and MultiProg do not require authentication, which allows remote attackers to execute arbitrary commands via protocol-compliant traffic.... Read more
- Published: Jan. 17, 2015
- Modified: Sep. 05, 2025
-
7.8
HIGHCVE-2014-9194
Arbiter 1094B GPS Substation Clock allows remote attackers to cause a denial of service (disruption) via crafted radio transmissions that spoof GPS satellite broadcasts.... Read more
Affected Products : 1094b_gps_substation_clock- Published: Jan. 17, 2015
- Modified: Jul. 29, 2025
-
8.5
HIGHCVE-2014-8143
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently ga... Read more
Affected Products : samba- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-5419
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier use the same RSA private key across different customers' installations, which makes it... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-5418
GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmware 5.2.0 and earlier allow remote attackers to cause a denial of service (resource consumption or reboot) v... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-2355
The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file.... Read more
Affected Products : intelligent_platforms_proficy_hmi\/scada_cimplicity- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025