Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2015-1201

    Privoxy before 3.0.22 allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.... Read more

    Affected Products : privoxy
    • Published: Jan. 20, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-1030

    Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests that are rejected because the socket limit is reached.... Read more

    Affected Products : privoxy
    • Published: Jan. 20, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-9494

    RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.... Read more

    Affected Products : rabbitmq
    • Published: Jan. 20, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-9491

    The devzvol_readdir function in illumos does not check the return value of a strchr call, which allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors.... Read more

    Affected Products : illumos
    • Published: Jan. 20, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-9490

    The numtok function in lib/raven/okjson.rb in the raven-ruby gem before 0.12.2 for Ruby allows remote attackers to cause a denial of service via a large exponent value in a scientific number.... Read more

    Affected Products : raven-ruby
    • Published: Jan. 20, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-9330

    Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, related to dimensions, which triggers an out-of-bounds read.... Read more

    Affected Products : libtiff
    • Published: Jan. 20, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-8790

    XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.... Read more

    Affected Products : getsimple_cms getsimple_cms
    • Published: Jan. 20, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2014-8625

    Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or... Read more

    Affected Products : dpkg
    • Published: Jan. 20, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2014-8386

    Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) display properties or (2) conditional bitmap parameter in a GNI file.... Read more

    Affected Products : adamview
    • Published: Jan. 20, 2015
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2015-0973

    Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers to execute arbitrary code via IDAT data with a large width, a different vulnerability than CVE-2014-9495.... Read more

    Affected Products : libpng mac_os_x solaris
    • Published: Jan. 18, 2015
    • Modified: Jun. 09, 2025
  • 3.5

    LOW
    CVE-2015-0862

    Multiple cross-site scripting (XSS) vulnerabilities in the management web UI in the RabbitMQ management plugin before 3.4.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) message details when a message is unqueued, such as... Read more

    Affected Products : rabbitmq_management
    • Published: Jan. 18, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2013-7252

    kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes it easier for attackers to guess passwords via a codebook attack.... Read more

    Affected Products : kde_applications
    • Published: Jan. 18, 2015
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2015-0924

    Ceragon FibeAir IP-10 bridges have a default password for the root account, which makes it easier for remote attackers to obtain access via a (1) HTTP, (2) SSH, (3) TELNET, or (4) CLI session.... Read more

    • Published: Jan. 17, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-0590

    Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a meeting-join action, aka Bug ID CSCuo34165.... Read more

    Affected Products : webex_meeting_center
    • Published: Jan. 17, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2014-6197

    IBM Security Network Protection 5.1.x and 5.2.x before 5.2.0.0 FP5 and 5.3.x before 5.3.0.0 FP1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.... Read more

    • Published: Jan. 17, 2015
    • Modified: Apr. 12, 2025
  • 2.1

    LOW
    CVE-2014-4835

    IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.... Read more

    • Published: Jan. 17, 2015
    • Modified: Apr. 12, 2025
  • 3.5

    LOW
    CVE-2014-3032

    Cross-site scripting (XSS) vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus 7.3.0 before 7.3.0.6, 7.3.1 before 7.3.1.7, and 7.4.0 before 7.4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more

    • Published: Jan. 17, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-3019

    IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage-pool access via a TELNET session.... Read more

    • Published: Jan. 17, 2015
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2014-3018

    IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to cause a denial of service (reboot) via a flood of IP packets.... Read more

    • Published: Jan. 17, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-9199

    The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equivalent traffic.... Read more

    Affected Products : java_web_client
    • Published: Jan. 17, 2015
    • Modified: Sep. 05, 2025
Showing 20 of 293592 Results