Latest CVE Feed
-
7.5
HIGHCVE-2014-6407
Docker before 1.3.2 allows remote attackers to write to arbitrary files and execute arbitrary code via a (1) symlink or (2) hard link attack in an image archive in a (a) pull or (b) load operation.... Read more
Affected Products : docker- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
2.9
LOWCVE-2014-6381
Juniper WLC devices with WLAN Software releases 8.0.x before 8.0.4, 9.0.x before 9.0.2.11, 9.0.3.x before 9.0.3.5, and 9.1.x before 9.1.1, when "Proxy ARP" or "No Broadcast" features are enabled in a clustered setup, allows remote attackers to cause a den... Read more
- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2013-4399
The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by reg... Read more
Affected Products : libvirt- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2014-9365
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the... Read more
- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8270
BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local system account, then performing a password reset.... Read more
Affected Products : track-it\!- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7265
Cross-site scripting (XSS) vulnerability in LinPHA allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : linpha- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
5.8
MEDIUMCVE-2014-6316
core/string_api.php in MantisBT before 1.2.18 does not properly categorize URLs when running under the web root, which allows remote attackers to conduct open redirect and phishing attacks via a crafted URL in the return parameter to login_page.php.... Read more
Affected Products : mantisbt- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6145
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence 10.1 before IF10, 10.1.1 before IF9, 10.2 before IF11, 10.2.1 before IF8, and 10.2.1.1 before IF7 allows remote authenticated users to inject arbitrary web script o... Read more
Affected Products : cognos_business_intelligence- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-6138
The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to bypass intended grid-data access restrictions via unspecified vectors.... Read more
Affected Products : websphere_datapower_xc10_appliance_firmware- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-4323
The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain start and length... Read more
Affected Products : linux_kernel- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7250
The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets.... Read more
- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4815
Session fixation vulnerability in IBM Rational Lifecycle Integration Adapter for Windchill 1.x before 1.0.1 allows remote attackers to hijack web sessions via unspecified vectors.... Read more
Affected Products : _ibm_rational_lifecycle_integration_adapter_for_windchill- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7263
Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP header, a different vulnerability than CVE-2014-7261.... Read more
Affected Products : i-httpd- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7262
Cross-site scripting (XSS) vulnerability in the Omake BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string.... Read more
Affected Products : i-httpd- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7261
Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string that is improperly rendered during construction of a directory index page, a different vulnerability than C... Read more
Affected Products : i-httpd- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7260
The Server Side Includes (SSI) implementation in the File Upload BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to execute arbitrary commands by uploading files containing commands in SSI directives.... Read more
Affected Products : i-httpd- Published: Dec. 12, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7264
Multiple cross-site scripting (XSS) vulnerabilities in admin/themes/default/pages/manage_users.twig in the Users Management feature in the admin component in Chyrp before 2.5.1 allow remote authenticated users to inject arbitrary web script or HTML via th... Read more
Affected Products : chyrp- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6215
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 before 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authenticated users to inject arbitrary web... Read more
Affected Products : websphere_portal- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6163
Cross-site scripting (XSS) vulnerability on the IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : websphere_datapower_xc10_appliance_firmware- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-6143
The IBM WebSphere DataPower XC10 appliance 2.1 and 2.5 before FP4 allows local users to obtain sensitive information by reading a response.... Read more
Affected Products : websphere_datapower_xc10_appliance_firmware- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025