CVE-2014-0 to CVE-2014-999
75 CVEs with public proof-of-concept exploits.
- CVE-2014-00071 PoCThe Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell…
- CVE-2014-00301 PoCThe XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified…
- CVE-2014-003810 PoCsThe compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to…
- CVE-2014-00401 PoCOpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, uses an HTTP connection to download…
- CVE-2014-00421 PoCOpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets gpgcheck to 0 for certain…
- CVE-2014-00504 PoCsMultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote…
- CVE-2014-00751 PoCInteger overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before…
- CVE-2014-00945 PoCsThe ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class…
- CVE-2014-01123 PoCsParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote…
- CVE-2014-01131 PoCCookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the…
- CVE-2014-01143 PoCsApache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products…
- CVE-2014-01301 PoCKEVDirectory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails…
- CVE-2014-016069 PoCsKEVThe (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows…
- CVE-2014-01651 PoCWordPress before 3.7.2 and 3.8.x before 3.8.2 allows remote authenticated users to publish posts by leveraging the Contributor role,…
- CVE-2014-01662 PoCsThe wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly…
- CVE-2014-01851 PoCsapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the…
- CVE-2014-01953 PoCsThe dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not…
- CVE-2014-01966 PoCsKEVThe n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the…
- CVE-2014-02246 PoCsOpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages,…
- CVE-2014-02265 PoCsRace condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service…
- CVE-2014-02421 PoCmod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the…
- CVE-2014-02432 PoCsCheck_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
- CVE-2014-02573 PoCsMicrosoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it is safe to…
- CVE-2014-02824 PoCsMicrosoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory…
- CVE-2014-03073 PoCsUse-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of…
- CVE-2014-03226 PoCsKEVUse-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via vectors…
- CVE-2014-03291 PoCThe TELNET service on the ZTE ZXV10 W300 router 2.1.0 has a hardcoded password ending with airocon for the admin account, which allows…
- CVE-2014-03341 PoCMultiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple allow remote authenticated users to inject arbitrary web script or…
- CVE-2014-03583 PoCsMultiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read arbitrary files via…
- CVE-2014-03722 PoCsUnspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server,…
- CVE-2014-03792 PoCsUnspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server,…
- CVE-2014-04721 PoCThe django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2…
- CVE-2014-04763 PoCsThe slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via…
- CVE-2014-04973 PoCsKEVInteger underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before…
- CVE-2014-05146 PoCsThe Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to…
- CVE-2014-05152 PoCsBuffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS X, and before…
- CVE-2014-05211 PoCAdobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X do not properly implement JavaScript APIs, which…
- CVE-2014-05562 PoCsHeap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before…
- CVE-2014-05692 PoCsInteger overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411…
- CVE-2014-06202 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to inject…
- CVE-2014-06212 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote attackers to…
- CVE-2014-06442 PoCsEMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an…
- CVE-2014-06592 PoCsThe Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1,…
- CVE-2014-06831 PoCThe web management interface on the Cisco RV110W firewall with firmware 1.2.0.9 and earlier, RV215W router with firmware 1.1.0.5 and…
- CVE-2014-07492 PoCsStack-based buffer overflow in lib/Libdis/disrsi_.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager)…
- CVE-2014-07502 PoCsGE Proficy HMI/SCADA Path Traversal
- CVE-2014-07631 PoCAdvantech WebAccess SQL Injection
- CVE-2014-07801 PoCKEVInduSoft Web Studio Path Traversal
- CVE-2014-07811 PoCYokogawa CENTUM CS 3000 Heap-based Buffer Overflow
- CVE-2014-07822 PoCsYokogawa CENTUM CS 3000 Stack-based Buffer Overflow
- CVE-2014-07832 PoCsYokogawa CENTUM CS 3000 Stack-based Buffer Overflow
- CVE-2014-07842 PoCsYokogawa CENTUM CS 3000 Stack-based Buffer Overflow
- CVE-2014-07871 PoCWellinTech KingSCADA Stack-based Buffer Overflow
- CVE-2014-07932 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for Joomla! allow…
- CVE-2014-07942 PoCsSQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to…
- CVE-2014-08161 PoCUnspecified vulnerability in Norman Security Suite 10.1 and earlier allows local users to gain privileges via unknown vectors.
- CVE-2014-08641 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in Executer in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0…
- CVE-2014-08651 PoCRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input…
- CVE-2014-08661 PoCRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext credentials over…
- CVE-2014-08671 PoCrcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows…
- CVE-2014-08681 PoCRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-side input…
- CVE-2014-08691 PoCThe decrypt function in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics does not…
- CVE-2014-08701 PoCMultiple cross-site scripting (XSS) vulnerabilities in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5…
- CVE-2014-08711 PoCRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows remote attackers to obtain…
- CVE-2014-08941 PoCRICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics allows context-dependent attackers…
- CVE-2014-09001 PoCThe Device Administrator code in Android before 4.4.1_r1 might allow attackers to spoof device administrators and consequently bypass MDM…
- CVE-2014-09101 PoCCross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, and 7.0.0…
- CVE-2014-09806 PoCsBuffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI file.
- CVE-2014-09812 PoCsVBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and…
- CVE-2014-09834 PoCsMultiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py…
- CVE-2014-09842 PoCsThe passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation of a Route…
- CVE-2014-09954 PoCsThe Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of service (uncontrolled…
- CVE-2014-09974 PoCsWiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung…
- CVE-2014-09981 PoCInteger signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to…
- CVE-2014-09992 PoCsSendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive information and…