Latest CVE Feed
-
7.8
HIGHCVE-2014-3382
The SQL*Net inspection engine in Cisco ASA Software 7.2 before 7.2(5.13), 8.2 before 8.2(5.50), 8.3 before 8.3(2.42), 8.4 before 8.4(7.15), 8.5 before 8.5(1.21), 8.6 before 8.6(1.14), 8.7 before 8.7(1.13), 9.0 before 9.0(4.5), and 9.1 before 9.1(5.1) allo... Read more
Affected Products : asa- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7226
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.... Read more
Affected Products : http_file_server- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7047
The Ocean Avenue Mobile Pro (aka com.oceanavenue.mobile) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : ocean_avenue_mobile_pro- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-7046
The George Wassouf (aka com.devkhr32.georgewassouf) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : george_wassouf- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-6439
Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : elasticsearch- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5351
The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold request, which allows remote authenticated users to forge tickets by leveraging... Read more
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-5298
FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blacklist and conduct unrestricted file upload attacks by uploading a file with an executable extension that c... Read more
Affected Products : x2engine- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-5297
The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP object injection and Server-Side Request Forgery (SSRF) attacks via crafted serialized data in the report par... Read more
Affected Products : x2engine- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-5270
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the abil... Read more
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4661
Cross-site scripting (XSS) vulnerability in HP Records Manager before 7.3.5 and 8.x before 8.1 Patch 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : records_manager- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.8
MEDIUMCVE-2014-3405
Cisco IOS XE enables the IPv6 Routing Protocol for Low-Power and Lossy Networks (aka RPL) on both the Autonomic Control Plane (ACP) and external Autonomic Networking Infrastructure (ANI) interfaces, which allows remote attackers to conduct route-injection... Read more
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3404
The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to trigger acceptance of an invalid message via crafted messages, aka Bug ID CSCuq22677.... Read more
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3403
The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to spoof devices via crafted messages, aka Bug ID CSCuq22647.... Read more
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3201
core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a certain IFRAME overflow condition, which allows remote attackers to spoof content via a crafted web site th... Read more
Affected Products : chrome- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-3147
Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a CSV file.... Read more
Affected Products : splunk- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-2649
Unspecified vulnerability in HP Operations Manager 9.20 on UNIX allows remote attackers to execute arbitrary code via unknown vectors.... Read more
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-2648
Unspecified vulnerability in HP Operations Manager 9.10 and 9.11 on UNIX allows remote attackers to execute arbitrary code via unknown vectors.... Read more
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2014-2646
Unspecified vulnerability in HP Network Automation 9.10 and 9.20 allows local users to bypass intended access restrictions via unknown vectors.... Read more
Affected Products : network_automation- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-2638
Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2344.... Read more
Affected Products : sprinter- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-2637
Unspecified vulnerability in HP Sprinter 12.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-2342.... Read more
Affected Products : sprinter- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025