Latest CVE Feed
-
5.0
MEDIUMCVE-2014-7259
SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain privileges via a crafted application.... Read more
Affected Products : kaku_san_sei_million_aruthur- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7258
Cross-site scripting (XSS) vulnerability in KENT-WEB Clip Board 2.91 and earlier, when running certain versions of Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : clip_board- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-7256
The (1) PPP Access Concentrator (PPPAC) and (2) Dial-Up Networking Internet Initiative Japan Inc. SEIL series routers SEIL/x86 Fuji 1.00 through 3.22; SEIL/X1, SEIL/X2, and SEIL/B1 1.00 through 4.62; SEIL/Turbo 1.82 through 2.18; and SEIL/neu 2FE Plus 1.8... Read more
Affected Products : seil_x86_fuji_firmware seil_x2_firmware seil_b1_firmware seil_x1_firmware seil_plus_firmware seil_plus seil_turbo_firmware seil_turbo seil_b1 seil_x2 +2 more products- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7255
Internet Initiative Japan Inc. SEIL Series routers SEIL/X1 2.50 through 4.62, SEIL/X2 2.50 through 4.62, SEIL/B1 2.50 through 4.62, and SEIL/x86 Fuji 1.70 through 3.22 allow remote attackers to cause a denial of service (CPU and traffic consumption) via a... Read more
Affected Products : seil_x86_fuji_firmware seil_x2_firmware seil_b1_firmware seil_x1_firmware seil_b1 seil_x2 seil_x1 seil_x86_fuji- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2014-7254
Unspecified vulnerability in ARROWS Me F-11D allows physically proximate attackers to read or modify flash memory via unknown vectors.... Read more
Affected Products : arrows_me_f-11d- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-7253
FUJITSU F-12C, ARROWS Tab LTE F-01D, ARROWS Kiss F-03D, and REGZA Phone T-01D for Android allows local users to execute arbitrary commands via unspecified vectors.... Read more
- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2014-7252
Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and Soft... Read more
Affected Products : disney_mobile arrows_tab_lte_f-01d softbank_102sh regza_phone_t-01d arrows_x_lte_f-05d prada_phone_l-02d f-08d- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7243
LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, which allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9140
Buffer overflow in the ppp_hdlc function in print-ppp.c in tcpdump 4.6.2 and earlier allows remote attackers to cause a denial of service (crash) cia a crafted PPP packet.... Read more
Affected Products : tcpdump- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8990
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.... Read more
- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8123
Buffer overflow in the bGetPPS function in wordole.c in Antiword 0.37 allows remote attackers to cause a denial of service (crash) via a crafted document.... Read more
Affected Products : antiword- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-6040
GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting (1) IBM933, (2) IBM935, (3) IBM937, (4) ... Read more
Affected Products : glibc- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-4703
lib/parse_ini.c in Nagios Plugins 2.0.2 allows local users to obtain sensitive information via a symlink attack on the configuration file in the extra-opts flag. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-4701.... Read more
Affected Products : nagios- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-4702
The check_icmp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4701.... Read more
Affected Products : nagios- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-4701
The check_dhcp plugin in Nagios Plugins before 2.0.2 allows local users to obtain sensitive information from INI configuration files via the extra-opts flag, a different vulnerability than CVE-2014-4702.... Read more
Affected Products : nagios- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3627
The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar arc... Read more
Affected Products : hadoop- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-3561
The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes.... Read more
Affected Products : enterprise_virtualization- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-2273
The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary memory locations via unspecified vectors.... Read more
- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2012-6656
iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8... Read more
- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9215
SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to execute arbitrary SQL commands via the email parameter in the register page to index.php. NOTE: the email p... Read more
Affected Products : pbboard- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025