Skip to main content

Year archive

CVEs published in 2014

Archive summary

7,928 CVEs published in 2014 — 793 Critical, 1,160 High, 5,317 Medium, 658 Low, 0 Unrated.

CVE-2013-7304

Published Jan 22, 2014

Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to sp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2750

Published Jan 22, 2014

Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0672

Published Jan 22, 2014

The Search and Play interface in Cisco MediaSense does not properly enforce authorization requirements, which allows remote authenticated users to download arbitrary recordings vi…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0671

Published Jan 22, 2014

Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0670

Published Jan 22, 2014

Cross-site scripting (XSS) vulnerability in the Search and Play interface in Cisco MediaSense allows remote attackers to inject arbitrary web script or HTML via an unspecified par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0669

Published Jan 22, 2014

The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attackers to bypass intended Top-Up pa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5987

Published Jan 21, 2014

Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 allows local users to bypass intended access restrictions for the GPU and gain privileges v…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5986

Published Jan 21, 2014

Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack vectors, a different vulnerability than CVE-2013-5987.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-4884

Published Jan 21, 2014

Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded sequences in a server response, w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4160

Published Jan 21, 2014

Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vect…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2152

Published Jan 21, 2014

Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted appli…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2151

Published Jan 21, 2014

Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-2104

Published Jan 21, 2014

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain us…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1923

Published Jan 21, 2014

rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted f…

CVSS 3.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1769

Published Jan 21, 2014

A certain hashing algorithm in Telepathy Gabble 0.16.x before 0.16.5 and 0.17.x before 0.17.3 allows remote attackers to cause a denial of service (NULL pointer dereference and cr…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0485

Published Jan 21, 2014

Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR13-FP16 has unknown impact and attack vectors related to Cla…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0157

Published Jan 21, 2014

(a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the existence of restricted directories by (1) using the --guess-…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-2997

Published Jan 21, 2014

XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to r…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7219

Published Jan 21, 2014

SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 7,526-7,550 of 7,928 CVEsPage 302 of 318