Latest CVE Feed
-
5.0
MEDIUMCVE-2014-8088
The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.... Read more
Affected Products : zend_framework- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7968
VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.... Read more
Affected Products : virtual_desktop_service_manager- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7183
Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query parameter or (2) QUERY_STRING.... Read more
Affected Products : litecart- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7182
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker... Read more
Affected Products : wp_go_maps- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-6387
gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.... Read more
Affected Products : mantisbt- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-6352
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- Actively Exploited
- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3677
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.... Read more
Affected Products : shim- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3676
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."... Read more
Affected Products : shim- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3675
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.... Read more
Affected Products : shim- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2013-7407
Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more
Affected Products : mrbs_module- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-4450
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within uninte... Read more
Affected Products : iphone_os- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-4449
iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : iphone_os- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
1.9
LOWCVE-2014-4448
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.... Read more
Affected Products : iphone_os- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3111
Multiple cross-site scripting (XSS) vulnerabilities in FOG 0.27 through 0.32 allow remote authenticated users to inject arbitrary web script or HTML via the (1) Printer Model field to the Printer Management page, (2) Image Name field to the Image Manageme... Read more
Affected Products : fog- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-2531
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action... Read more
Affected Products : web_control_panel- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8380
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer Header in a "404 Not Found" response. NOTE: this vulnerability might exist because of a CVE-2010-2429 regression.... Read more
Affected Products : splunk- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8379
Multiple cross-site scripting (XSS) vulnerabilities in the Marketo MA module before 7.x-1.5 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to field titles to the (1) Webform ... Read more
Affected Products : marketo_ma- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8378
Cross-site scripting (XSS) vulnerability in the TableField module 7.x-2.x before 7.x-2.3 allows remote authenticated users with the "administer content types" or "administer taxonomy" permission to inject arbitrary web script or HTML via vectors related t... Read more
Affected Products : tablefield- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8377
Cross-site scripting (XSS) vulnerability in Webasyst Shop-Script 5.2.2.30933 allows remote attackers to inject arbitrary web script or HTML via the phone number field in a new contact to phpecom/index.php/webasyst/contacts/.... Read more
Affected Products : shop-script- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8376
Cross-site scripting (XSS) vulnerability in the context administration sub-panel in the Site Banner module before 7.x-4.1 for Drupal allows remote authenticated users with the "Administer contexts" Context UI module permission to inject arbitrary web scri... Read more
Affected Products : site_banner- Published: Oct. 21, 2014
- Modified: Apr. 12, 2025