Total
5231 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-9493 | 2 Openstack, Redhat | 2 Image Registry And Delivery Service \(glance\), Openstack | 2024-11-21 | 5.5 MEDIUM | N/A |
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property. | |||||
CVE-2014-9476 | 1 Mediawiki | 1 Mediawiki | 2024-11-21 | 5.0 MEDIUM | N/A |
MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAXdomains via a domain that has a partial match to an allowed origin, as demonstrated by "http://en.wikipedia.org.evilsite.example/." | |||||
CVE-2014-9466 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 4.0 MEDIUM | N/A |
Open-Xchange (OX) AppSuite and Server before 7.4.2-rev42, 7.6.0 before 7.6.0-rev36, and 7.6.1 before 7.6.1-rev14 does not properly handle directory permissions, which allows remote authenticated users to read files via unspecified vectors, related to the "folder identifier." | |||||
CVE-2014-9387 | 1 Sap | 1 Businessobjects | 2024-11-21 | 10.0 HIGH | N/A |
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORBA call, aka SAP Note 2039905. | |||||
CVE-2014-9357 | 1 Docker | 1 Docker | 2024-11-21 | 10.0 HIGH | N/A |
Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (.xz) archive, related to the chroot for archive extraction. | |||||
CVE-2014-9353 | 1 Netapp | 1 Oncommand Balance | 2024-11-21 | 10.0 HIGH | N/A |
NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors. | |||||
CVE-2014-9324 | 1 Otrs | 1 Otrs Help Desk | 2024-11-21 | 6.0 MEDIUM | N/A |
The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before 3.3.11, and 4.0.x before 4.0.3 allows remote authenticated users to access and modify arbitrary tickets via unspecified vectors. | |||||
CVE-2014-9304 | 1 Plex | 1 Media Server | 2024-11-21 | 7.5 HIGH | N/A |
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server. | |||||
CVE-2014-9262 | 1 Snapcreek | 1 Duplicator | 2024-11-21 | 5.5 MEDIUM | 8.2 HIGH |
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files. | |||||
CVE-2014-9260 | 1 Downloadmanager | 1 Download Manager | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option. | |||||
CVE-2014-9249 | 1 Zenoss | 1 Zenoss Core | 2024-11-21 | 7.5 HIGH | N/A |
The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open ports, aka ZEN-15408. | |||||
CVE-2014-9226 | 2 Broadcom, Symantec | 2 Symantec Critical System Protection, Data Center Security | 2024-11-21 | 7.2 HIGH | N/A |
The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x through 6.0 MP1 allows local users to bypass intended Protection Policies via unspecified vectors. | |||||
CVE-2014-9193 | 1 Innominate | 1 Mguard Firmware | 2024-11-21 | 9.0 HIGH | N/A |
Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting. | |||||
CVE-2014-9141 | 1 Thomsonreuters | 1 Fixed Assets Cs | 2024-11-21 | 7.2 HIGH | N/A |
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program. | |||||
CVE-2014-9135 | 1 Huawei | 2 P7-l10, P7-l10 Firmware | 2024-11-21 | 4.3 MEDIUM | N/A |
The PackageInstaller module in Huawei P7-L10 smartphones before V100R001C00B136 allows remote attackers to spoof the origin website and bypass the website whitelist protection mechanism via a crafted package. | |||||
CVE-2014-9113 | 1 Cchgroup | 1 Prosystem Fx Engagement | 2024-11-21 | 7.2 HIGH | N/A |
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\, which allows local users to obtain LocalSystem privileges via a Trojan horse file. | |||||
CVE-2014-9091 | 1 Icecast | 1 Icecast | 2024-11-21 | 4.6 MEDIUM | N/A |
Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors. | |||||
CVE-2014-9048 | 1 Owncloud | 1 Owncloud | 2024-11-21 | 5.0 MEDIUM | N/A |
The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote attackers to bypass the password-protection for shared files via the API. | |||||
CVE-2014-9026 | 1 Ubercart | 1 Ubercart | 2024-11-21 | 4.0 MEDIUM | N/A |
The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtain sensitive information via unspecified vectors. | |||||
CVE-2014-9024 | 1 Protected Pages Project | 1 Protected Pages | 2024-11-21 | 7.5 HIGH | N/A |
The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path. |