Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2014-8542

    libavcodec/utils.c in FFmpeg before 2.4.2 omits a certain codec ID during enforcement of alignment, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted JV data.... Read more

    Affected Products : ubuntu_linux debian_linux ffmpeg
    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2014-8541

    libavcodec/mjpegdec.c in FFmpeg before 2.4.2 considers only dimension differences, and not bits-per-pixel differences, when determining whether an image size has changed, which allows remote attackers to cause a denial of service (out-of-bounds access) or... Read more

    Affected Products : ubuntu_linux ffmpeg
    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 3.5

    LOW
    CVE-2014-8326

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) table ... Read more

    Affected Products : phpmyadmin opensuse
    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2014-5417

    Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2014-5408

    Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more

    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2014-4834

    IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application crash) via a crafted XM... Read more

    Affected Products : websphere_commerce
    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2014-4810

    IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between the Cognos Mobile server and the Cognos Business Intelligence server after a logoff action on a mobile device, which makes it easier for ... Read more

    Affected Products : cognos_mobile
    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 4.0

    MEDIUM
    CVE-2014-4769

    IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity ref... Read more

    Affected Products : websphere_commerce
    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-3710

    The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and applicatio... Read more

    Affected Products : ubuntu_linux debian_linux php
    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2014-2374

    The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.... Read more

    Affected Products : axm-net acuvim_ii
    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2014-2373

    The web server on the AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to bypass authentication and modify settings via a direct request to an unspecified URL.... Read more

    Affected Products : axm-net acuvim_ii
    • Published: Nov. 05, 2014
    • Modified: Apr. 12, 2025
  • 7.1

    HIGH
    CVE-2014-2718

    ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which a... Read more

    • Published: Nov. 04, 2014
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2014-3461

    hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."... Read more

    Affected Products : qemu
    • Published: Nov. 04, 2014
    • Modified: Apr. 12, 2025
  • 4.6

    MEDIUM
    CVE-2014-0223

    Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.... Read more

    Affected Products : qemu linux_enterprise_server
    • Published: Nov. 04, 2014
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2014-0222

    Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.... Read more

    Affected Products : qemu linux_enterprise_server
    • Published: Nov. 04, 2014
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2014-0182

    Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted config length in a savevm image.... Read more

    Affected Products : qemu
    • Published: Nov. 04, 2014
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2013-6399

    Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.... Read more

    Affected Products : qemu
    • Published: Nov. 04, 2014
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2013-4542

    The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.... Read more

    Affected Products : qemu
    • Published: Nov. 04, 2014
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2013-4541

    The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.... Read more

    Affected Products : qemu
    • Published: Nov. 04, 2014
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2013-4540

    Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.... Read more

    Affected Products : qemu opensuse
    • Published: Nov. 04, 2014
    • Modified: Apr. 12, 2025
Showing 20 of 293962 Results