Latest CVE Feed
-
4.3
MEDIUMCVE-2014-2336
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 and FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerabi... Read more
- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2335
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiManager before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.... Read more
- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-2334
Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface in Fortinet FortiAnalyzer before 5.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2014-2336.... Read more
Affected Products : fortianalyzer_firmware- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2013-0334
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.... Read more
- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6150
Cross-site scripting (XSS) vulnerability in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.0 through 7.2.1.6 and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : tivoli_application_dependency_discovery_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-6148
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 does not require TADDM authentication for rptdesign downloads, which allows remote authenticated users to obtain sen... Read more
Affected Products : tivoli_application_dependency_discovery_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6101
Cross-site scripting (XSS) vulnerability in the redirect-login feature in IBM Business Process Manager (BPM) Advanced 7.5 through 8.5.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : business_process_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3375
Multiple cross-site scripting (XSS) vulnerabilities in the CCM Service interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90597.... Read more
Affected Products : unified_communications_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3374
Multiple cross-site scripting (XSS) vulnerabilities in the CCM admin interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90582.... Read more
Affected Products : unified_communications_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3373
Multiple cross-site scripting (XSS) vulnerabilities in the CCM Dialed Number Analyzer interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCu... Read more
Affected Products : unified_communications_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3372
Multiple cross-site scripting (XSS) vulnerabilities in the CCM reports interface in the Server in Cisco Unified Communications Manager allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuq90589.... Read more
Affected Products : unified_communications_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-3366
SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted response, aka Bug ID CSCup88089.... Read more
Affected Products : unified_communications_manager- Published: Oct. 31, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .m3u (playlist) file.... Read more
Affected Products : allplayer- Published: Oct. 30, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-3684
The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and earlier does not validate that the owner of the process also owns the adopted session id, which allows remo... Read more
Affected Products : torque_resource_manager- Published: Oct. 30, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3623
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers... Read more
- Published: Oct. 30, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3584
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.... Read more
Affected Products : cxf- Published: Oct. 30, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3446
SQL injection vulnerability in wcm/system/pages/admin/getnode.aspx in BSS Continuity CMS 4.2.22640.0 allows remote attackers to execute arbitrary SQL commands via the nodeid parameter.... Read more
Affected Products : continuity_cms- Published: Oct. 30, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2013-3304
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.... Read more
Affected Products : equallogic_ps4000_firmware- Published: Oct. 30, 2014
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2014-7877
Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.... Read more
Affected Products : hp-ux- Published: Oct. 30, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-8538
The Hijab Modern (aka com.Aisyaidea.HijabModern) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : hijab_modern- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025