Latest CVE Feed
-
4.3
MEDIUMCVE-2014-5408
Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4834
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption, and application crash) via a crafted XM... Read more
Affected Products : websphere_commerce- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4810
IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between the Cognos Mobile server and the Cognos Business Intelligence server after a logoff action on a mobile device, which makes it easier for ... Read more
Affected Products : cognos_mobile- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
4.0
MEDIUMCVE-2014-4769
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity ref... Read more
Affected Products : websphere_commerce- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3710
The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to cause a denial of service (out-of-bounds read and applicatio... Read more
- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-2374
The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors involving JavaScript.... Read more
- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-2373
The web server on the AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to bypass authentication and modify settings via a direct request to an unspecified URL.... Read more
- Published: Nov. 05, 2014
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2014-2718
ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and possibly other RT-series routers before firmware 3.0.0.4.376.x do not verify the integrity of firmware (1) update information or (2) downloaded updates, which a... Read more
- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-3461
hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
4.6
MEDIUMCVE-2014-0223
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.... Read more
- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-0222
Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.... Read more
- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-0182
Heap-based buffer overflow in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted config length in a savevm image.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-6399
Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4542
The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4541
The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4540
Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.... Read more
- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4539
Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm im... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4538
Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col val... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4537
The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-4534
Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.... Read more
Affected Products : qemu- Published: Nov. 04, 2014
- Modified: Apr. 12, 2025