Latest CVE Feed
-
5.4
MEDIUMCVE-2014-5860
The Slide Show Creator (aka com.amem) application 4.4.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : slide_show_creator- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5859
The Star Girl: Colors of Spring (aka com.animoca.google.starGirlSpring) application 3.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cra... Read more
Affected Products : star_girl\- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5858
The Candy Blast (aka com.appgame7.candyblast) application 1.1.001 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : candy_blast- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2014-5857
The White & Yellow Pages (aka com.avantar.wny) application 5.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : white_\&_yellow_pages- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-5313
Cross-site scripting (XSS) vulnerability in the management page in Six Apart Movable Type before 5.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2014-4864
The NETGEAR ProSafe Plus Configuration Utility creates configuration backup files containing cleartext passwords, which might allow remote attackers to obtain sensitive information by reading a file.... Read more
- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-4789
Session fixation vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote attackers to hijack web sessions via unspecified vectors.... Read more
Affected Products : initiate_master_data_service- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-4788
IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obtain... Read more
Affected Products : initiate_master_data_service- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-4787
Cross-site scripting (XSS) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated users to inject arbitrary web script or HTML via un... Read more
Affected Products : initiate_master_data_service- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2014-4786
IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and ... Read more
Affected Products : initiate_master_data_service- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2014-4785
Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote authenticated users to hijack the authentication of arbitr... Read more
Affected Products : initiate_master_data_service- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-4784
IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not properly restrict use of FRAME elements, which allows remote attackers to conduct phishing attacks, and bypass int... Read more
Affected Products : initiate_master_data_service- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-4783
Cross-site request forgery (CSRF) vulnerability in IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 allows remote attackers to hijack the authentication of arbitrary users ... Read more
Affected Products : initiate_master_data_service- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-4756
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to hijack sessions via unspecified vectors.... Read more
Affected Products : rational_license_key_server- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-3348
The SSH module in the Integrated Management Controller (IMC) before 2.3.1 in Cisco Unified Computing System on E-Series blade servers allows remote attackers to cause a denial of service (IMC hang) via a crafted SSH packet, aka Bug ID CSCuo69206.... Read more
- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-3343
Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (DHCPv6 daemon crash) via a malformed DHCPv6 packet, aka Bug ID CSCuo59052.... Read more
Affected Products : ios_xr- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3179
Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.120 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
Affected Products : chrome- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3178
Use-after-free vulnerability in core/dom/Node.cpp in Blink, as used in Google Chrome before 37.0.2062.120, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of render-tree incons... Read more
Affected Products : chrome- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2014-3079
The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 allows remote authenticated users to bypass authorization checks and visit unspecified URLs with license-usage data via a DESCRIBE clause in a SPARQL qu... Read more
Affected Products : rational_license_key_server- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2014-3037
Cross-site request forgery (CSRF) vulnerability in IBM Configuration Management Application (aka VVC) in IBM Rational Engineering Lifecycle Manager before 4.0.7 and 5.x before 5.0.1, Rational Software Architect Design Manager before 4.0.7 and 5.x before 5... Read more
- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025