Latest CVE Feed
-
5.8
MEDIUMCVE-2014-2230
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest ... Read more
Affected Products : openx- Published: Oct. 23, 2014
- Modified: Apr. 12, 2025
-
6.9
MEDIUMCVE-2014-0619
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.... Read more
Affected Products : hamster_free_zip_archiver- Published: Oct. 23, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-4766
IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading an exported Record and Playback (RAP) file.... Read more
Affected Products : classic_meeting_server- Published: Oct. 23, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-3829
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the c... Read more
- Published: Oct. 23, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-3828
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allow remote attackers to execute arbitrary SQL commands via (1) the index_id parameter to views/graphs/common/makeXML_ListMetrics.ph... Read more
- Published: Oct. 23, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8764
DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind.... Read more
- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8763
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind.... Read more
- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8762
The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter.... Read more
Affected Products : dokuwiki- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8761
inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.... Read more
Affected Products : dokuwiki- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8381
Multiple cross-site scripting (XSS) vulnerabilities in Megapolis.Portal Manager allow remote attackers to inject arbitrary web script or HTML via the (1) dateFrom or (2) dateTo parameter.... Read more
Affected Products : megapolis.portal_manager- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2014-8325
The Calendar Base (cal) extension before 1.5.9 and 1.6.x before 1.6.1 for TYPO3 allows remote attackers to cause a denial of service (resource consumption) via vectors related to the PHP PCRE library.... Read more
Affected Products : calender_base- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8088
The (1) Zend_Ldap class in Zend before 1.12.9 and (2) Zend\Ldap component in Zend 2.x before 2.2.8 and 2.3.x before 2.3.3 allows remote attackers to bypass authentication via a password starting with a null byte, which triggers an unauthenticated bind.... Read more
Affected Products : zend_framework- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-7968
VDSM allows remote attackers to cause a denial of service (connection blocking) by keeping an SSL connection open.... Read more
Affected Products : virtual_desktop_service_manager- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7183
Multiple cross-site scripting (XSS) vulnerabilities in the search.php in LiteCart 1.1.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) query parameter or (2) QUERY_STRING.... Read more
Affected Products : litecart- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-7182
Multiple cross-site scripting (XSS) vulnerabilities in the WP Google Maps plugin before 6.0.27 for WordPress allow remote attackers to inject arbitrary web script or HTML via the poly_id parameter in an (1) edit_poly, (2) edit_polyline, or (3) edit_marker... Read more
Affected Products : wp_go_maps- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-6387
gpc_api.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.... Read more
Affected Products : mantisbt- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-6352
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- Actively Exploited
- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3677
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.... Read more
Affected Products : shim- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3676
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."... Read more
Affected Products : shim- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3675
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.... Read more
Affected Products : shim- Published: Oct. 22, 2014
- Modified: Apr. 12, 2025