Latest CVE Feed
-
3.5
LOWCVE-2014-7979
Cross-site scripting (XSS) vulnerability in the SimpleCorp theme 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.... Read more
Affected Products : simplecorp- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-7978
Cross-site scripting (XSS) vulnerability in the BlueMasters theme 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via vectors related to theme settings.... Read more
Affected Products : bluemasters- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-7205
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.... Read more
Affected Products : bassmaster- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2014-7185
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-6394
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" d... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2014-5308
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name parameter in a Search action to lib/project/projectView.php or (2) id parameter to lib/events/eventinfo.php.... Read more
Affected Products : testlink- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7967
Multiple unspecified vulnerabilities in Google V8 before 3.28.71.15, as used in Google Chrome before 38.0.2125.101, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3200
Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3199
The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an erroneous fallback outcome for wrapper-selection failures, which allows remote attackers to cause a denial of... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3198
The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of ... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3197
The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attacke... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3196
base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.... Read more
Affected Products : chrome- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3195
Google V8, as used in Google Chrome before 38.0.2125.101, does not properly track JavaScript heap-memory allocations as allocations of uninitialized memory and does not properly concatenate arrays of double-precision floating-point numbers, which allows r... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3194
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3193
The SessionService::GetLastSession function in browser/sessions/session_service.cc in Google Chrome before 38.0.2125.101 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors that lever... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3192
Use-after-free vulnerability in the ProcessingInstruction::setXSLStyleSheet function in core/dom/ProcessingInstruction.cpp in the DOM implementation in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of serv... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3191
Use-after-free vulnerability in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers a widget-position update that im... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3190
Use-after-free vulnerability in the Event::currentTarget function in core/events/Event.cpp in Blink, as used in Google Chrome before 38.0.2125.101, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3189
The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate image-data dimensions, which allows remote attackers to cause a denial of service (out-of-bounds read) or poss... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-3188
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an e... Read more
- Published: Oct. 08, 2014
- Modified: Apr. 12, 2025