원본기사확인하기: [US-CERT: Bulletin(SB14-188)] 2014년 6월 30일까지 발표된 보안 취약점
The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores:
-
High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0
-
Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9
-
Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9
Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis.
High Vulnerabilities
Primary Vendor -- Product |
Description | Published | CVSS Score | Source & Patch Info |
---|---|---|---|---|
N/A -- N/A | Timbre SketchUp (formerly Google SketchUp) before 8 Maintenance 2 allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers a stack-based buffer overflow. | 2014-07-01 | 9.3 | CVE-2013-3662 XF MISC BUGTRAQ |
N/A -- N/A | Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3662. NOTE: this issue was SPLIT due to different affected products and codebases (ADT1); CVE-2013-7388 has been assigned to the paintlib issue. | 2014-07-01 | 9.3 | CVE-2013-3664 XF BID MISC SECUNIA MISC BUGTRAQ |
N/A -- N/A | Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed bitmap (BMP). NOTE: this issue was SPLIT from CVE-2013-3664 due to different affected products and codebases (ADT1). | 2014-07-01 | 9.3 | CVE-2013-7388 XF BID MISC SECUNIA MISC |
N/A -- N/A | Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that sends IPC messages. | 2014-07-01 | 10.0 | CVE-2014-1356 APPLE APPLE APPLE |
N/A -- N/A | Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that generates log messages. | 2014-07-01 | 10.0 | CVE-2014-1357 APPLE APPLE APPLE |
N/A -- N/A | Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application. | 2014-07-01 | 10.0 | CVE-2014-1358 APPLE APPLE APPLE |
N/A -- N/A | Integer underflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application. | 2014-07-01 | 10.0 | CVE-2014-1359 APPLE APPLE APPLE |
N/A -- N/A | Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message. | 2014-07-01 | 7.5 | CVE-2014-1371 APPLE |
N/A -- N/A | Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL API call, which allows attackers to execute arbitrary code via a crafted application. | 2014-07-01 | 10.0 | CVE-2014-1373 APPLE |
N/A -- N/A | Intel Compute in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenCL API call, which allows attackers to execute arbitrary code via a crafted application. | 2014-07-01 | 10.0 | CVE-2014-1376 APPLE |
N/A -- N/A | Array index error in IOAcceleratorFamily in Apple OS X before 10.9.4 allows attackers to execute arbitrary code via a crafted application. | 2014-07-01 | 10.0 | CVE-2014-1377 APPLE |
N/A -- N/A | Graphics Drivers in Apple OS X before 10.9.4 allows attackers to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a 32-bit executable file for a crafted application. | 2014-07-01 | 10.0 | CVE-2014-1379 APPLE |
N/A -- N/A | Thunderbolt in Apple OS X before 10.9.4 does not properly restrict IOThunderBoltController API calls, which allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted call. | 2014-07-01 | 10.0 | CVE-2014-1381 APPLE |
N/A -- N/A | Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to gain privileges via unknown vectors. | 2014-06-28 | 9.0 | CVE-2014-2613 |
N/A -- N/A | The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program. | 2014-07-02 | 7.2 | CVE-2014-3074 XF |
N/A -- N/A | Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure." | 2014-06-28 | 10.0 | CVE-2014-4648 |
Medium Vulnerabilities
Primary Vendor -- Product |
Description | Published | CVSS Score | Source & Patch Info |
---|---|---|---|---|
N/A -- N/A | Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown vectors. | 2014-06-27 | 6.4 | CVE-2011-1381 |
N/A -- N/A | IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login credentials via an unspecified injection. | 2014-06-27 | 4.9 | CVE-2013-6308 XF |
N/A -- N/A | IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct transactions, via an unspecified link injection. | 2014-06-27 | 6.0 | CVE-2013-6309 XF |
N/A -- N/A | SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | 2014-06-27 | 6.5 | CVE-2013-6311 XF |
N/A -- N/A | IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.33, 8.0.x before 8.0.0.9, and 8.5.x before 8.5.5.2 allows remote attackers to obtain sensitive information by leveraging incorrect request handling by the (1) Proxy or (2) ODR server. | 2014-06-27 | 5.0 | CVE-2014-0891 XF AIXAPAR |
N/A -- N/A | WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4. | 2014-07-01 | 6.8 | CVE-2014-1325 APPLE APPLE APPLE |
N/A -- N/A | WebKit, as used in Apple Safari before 6.1.5 and 7.x before 7.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1. | 2014-07-01 | 6.8 | CVE-2014-1340 APPLE |
N/A -- N/A | WebKit in Apple iOS before 7.1.2 and Apple Safari before 6.1.5 and 7.x before 7.0.5 does not properly encode domain names in URLs, which allows remote attackers to spoof the address bar via a crafted web site. | 2014-07-01 | 4.3 | CVE-2014-1345 APPLE APPLE |
N/A -- N/A | Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an invalid URL. | 2014-07-01 | 6.8 | CVE-2014-1349 APPLE |
N/A -- N/A | Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management. | 2014-07-01 | 4.6 | CVE-2014-1350 APPLE |
N/A -- N/A | CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image data. | 2014-07-01 | 6.8 | CVE-2014-1354 APPLE |
N/A -- N/A | The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in IOReporting in Apple OS X before 10.9.4, allows local users to cause a denial of service (NULL pointer dereference and reboot) via crafted API arguments. | 2014-07-01 | 4.9 | CVE-2014-1355 APPLE APPLE APPLE |
N/A -- N/A | Secure Transport in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 does not ensure that a DTLS message is accepted only for a DTLS connection, which allows remote attackers to obtain potentially sensitive information from uninitialized process memory by providing a DTLS message within a TLS connection. | 2014-07-01 | 5.0 | CVE-2014-1361 APPLE APPLE APPLE |
N/A -- N/A | WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4. | 2014-07-01 | 6.8 | CVE-2014-1362 APPLE APPLE APPLE |
N/A -- N/A | WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4. | 2014-07-01 | 6.8 | CVE-2014-1363 APPLE APPLE APPLE |
N/A -- N/A | WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4. | 2014-07-01 | 6.8 | CVE-2014-1364 APPLE APPLE APPLE |
N/A -- N/A | WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4. | 2014-07-01 | 6.8 | CVE-2014-1365 APPLE APPLE APPLE |
N/A -- N/A | WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4. | 2014-07-01 | 6.8 | CVE-2014-1366 APPLE APPLE APPLE |
N/A -- N/A | WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4. | 2014-07-01 | 6.8 | CVE-2014-1367 APPLE APPLE APPLE |
N/A -- N/A | WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4. | 2014-07-01 | 6.8 | CVE-2014-1368 APPLE APPLE APPLE |
N/A -- N/A | WebKit in Apple Safari before 6.1.5 and 7.x before 7.0.5 allows user-assisted remote attackers to access file: URLs by leveraging a URL drag operation that originates at a crafted web site. | 2014-07-01 | 4.3 | CVE-2014-1369 APPLE |
N/A -- N/A | The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive. | 2014-07-01 | 6.8 | CVE-2014-1370 APPLE |
N/A -- N/A | Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during processing of an unspecified system call, which allows local users to obtain sensitive information from kernel memory and bypass the ASLR protection mechanism via a crafted call. | 2014-07-01 | 4.9 | CVE-2014-1372 APPLE |
N/A -- N/A | WebKit, as used in Apple iOS before 7.1.2, Apple Safari before 6.1.5 and 7.x before 7.0.5, and Apple TV before 6.1.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-06-30-1, APPLE-SA-2014-06-30-3, and APPLE-SA-2014-06-30-4. | 2014-07-01 | 6.8 | CVE-2014-1382 APPLE APPLE APPLE |
N/A -- N/A | Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspecified vectors. | 2014-07-01 | 5.5 | CVE-2014-1383 APPLE |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2014-06-27 | 4.3 | CVE-2014-2006 JVNDB JVN CONFIRM |
N/A -- N/A | Session fixation vulnerability in the Report Advisor (RA) component in EMC Network Configuration Manager (NCM) before 9.3 allows remote attackers to hijack web sessions via a session cookie. | 2014-06-30 | 5.4 | CVE-2014-2509 BUGTRAQ |
N/A -- N/A | Unspecified vulnerability in HP Release Control 9.x before 9.13 p3 and 9.2x before RC 9.21.0003 p1 on Windows and 9.2x before RC 9.21.0002 p1 on Linux allows remote authenticated users to obtain sensitive information via unknown vectors. | 2014-06-28 | 4.0 | CVE-2014-2612 |
N/A -- N/A | IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to conduct link injection attacks via unspecified vectors. | 2014-06-27 | 5.0 | CVE-2014-3011 |
N/A -- N/A | IBM Tivoli Endpoint Manager 9.1 before 9.1.1088.0 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 2014-07-02 | 5.0 | CVE-2014-3066 XF |
N/A -- N/A | stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by replacing a text/plain .txt upload with an application/octet-stream .exe upload. | 2014-07-01 | 5.5 | CVE-2014-3088 BID MISC |
N/A -- N/A | Stack-based buffer overflow in the encode_key function in /system/bin/keystore in the KeyStore service in Android 4.3 allows attackers to execute arbitrary code, and consequently obtain sensitive key information or bypass intended restrictions on cryptographic operations, via a long key name. | 2014-07-02 | 5.1 | CVE-2014-3100 MISC |
N/A -- N/A | Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug IDs CSCui36937, CSCui37004, and CSCui36927. | 2014-07-02 | 4.0 | CVE-2014-3297 |
N/A -- N/A | Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive information by reading HTML source code, aka Bug ID CSCui36976. | 2014-07-02 | 4.0 | CVE-2014-3298 |
N/A -- N/A | The DHCP client implementation in Universal Small Cell firmware on Cisco Small Cell products allows remote attackers to execute arbitrary commands via crafted DHCP messages, aka Bug ID CSCup47513. | 2014-07-02 | 6.8 | CVE-2014-3307 |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to inject arbitrary web script or HTML via the Name field to the New Host groups page, related to create, update, and destroy notification boxes. | 2014-07-01 | 4.3 | CVE-2014-3491 |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in the host YAML view in Foreman before 1.4.5 and 1.5.x before 1.5.1 allow remote attackers to inject arbitrary web script or HTML via a parameter (1) name or (2) value related to the host. | 2014-07-01 | 4.3 | CVE-2014-3492 |
N/A -- N/A | kio/usernotificationhandler. |
2014-07-01 | 4.3 | CVE-2014-3494 BID |
N/A -- N/A | Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authentication of arbitrary users. | 2014-06-27 | 6.8 | CVE-2014-3881 JVNDB CONFIRM JVN |
N/A -- N/A | silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via crafted data in the Options field of a TCP header, a different vulnerability than CVE-2014-3890. | 2014-07-02 | 5.0 | CVE-2014-3889 |
N/A -- N/A | silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via a crafted IP packet, a different vulnerability than CVE-2014-3889. | 2014-07-02 | 5.0 | CVE-2014-3890 |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in server/offline.php in the ActiveHelper LiveHelp Live Chat plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MESSAGE, (2) EMAIL, or (3) NAME parameter. | 2014-07-01 | 4.3 | CVE-2014-4513 |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in mce_anyfont/dialog.php in the AnyFont plugin 2.2.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the text parameter. | 2014-07-01 | 4.3 | CVE-2014-4515 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in bicm-carousel-preview.php in the BIC Media Widget plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the param parameter. | 2014-07-01 | 4.3 | CVE-2014-4516 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in xd_resize.php in the Contact Form by ContactMe.com plugin 2.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter. | 2014-07-01 | 4.3 | CVE-2014-4518 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in phprack.php in the DMCA WaterMarker plugin before 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the plugin_dir parameter. | 2014-07-01 | 4.3 | CVE-2014-4520 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in client-assist.php in the dsIDXpress IDX plugin before 2.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. | 2014-07-01 | 4.3 | CVE-2014-4521 CONFIRM |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in client-assist.php in the dsSearchAgent: WordPress Edition plugin 1.0-beta10 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. | 2014-07-02 | 4.3 | CVE-2014-4522 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in classes/custom-image/media.php in the WP Easy Post Types plugin before 1.4.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ref parameter. | 2014-07-02 | 4.3 | CVE-2014-4524 MISC MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in callback.php in the efence plugin 1.3.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) zoneid, (3) pubKey, or (4) privKey parameter. | 2014-07-02 | 4.3 | CVE-2014-4526 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in paginas/vista-previa-form.php in the EnvialoSimple: Email Marketing and Newsletters (envialosimple-email- |
2014-07-02 | 4.3 | CVE-2014-4527 CONFIRM MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in admin/swarm-settings.php in the Bugs Go Viral : Facebook Promotion Generator (fbpromotions) plugin 1.3.4 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) promo_type, (2) fb_edit_action, or (3) promo_id parameter. | 2014-07-01 | 4.3 | CVE-2014-4528 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in fpg_preview.php in the Flash Photo Gallery plugin 0.7 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the path parameter. | 2014-07-02 | 4.3 | CVE-2014-4529 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in main_page.php in the Game tabs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the n parameter. | 2014-07-02 | 4.3 | CVE-2014-4531 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in templates/printAdminUsersList_ |
2014-07-02 | 4.3 | CVE-2014-4532 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in ajax_functions.php in the GEO Redirector plugin 1.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the hid_id parameter. | 2014-07-01 | 4.3 | CVE-2014-4533 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in videoplayer/autoplay.php in the HTML5 Video Player with Playlist plugin 2.4.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) theme or (2) playlistmod parameter. | 2014-07-02 | 4.3 | CVE-2014-4534 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in inpage.tpl.php in the Keyword Strategy Internal Links plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) sort, (2) search, or (3) dir parameter. | 2014-07-02 | 4.3 | CVE-2014-4537 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the query parameter. | 2014-07-01 | 4.3 | CVE-2014-4538 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in oleggo-twitter/twitter_login_ |
2014-07-02 | 4.3 | CVE-2014-4540 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in shortcode-generator/preview- |
2014-07-02 | 4.3 | CVE-2014-4541 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in redirect.php in the Ooorl plugin for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 2014-07-02 | 4.3 | CVE-2014-4542 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in payper/payper.php in the Pay Per Media Player plugin 1.24 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fcolor, (2) links, (3) stitle, (4) height, (5) width, (6) host, (7) bcolor, (8) msg, (9) id, or (10) size parameter. | 2014-07-02 | 4.3 | CVE-2014-4543 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in pq_dialog.php in the Pro Quoter plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) leftorright or (2) author parameter. | 2014-07-01 | 4.3 | CVE-2014-4545 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in book_ajax.php in the Rezgo plugin 1.4.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the response parameter. | 2014-07-02 | 4.3 | CVE-2014-4546 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in templates/default/index_ajax. |
2014-07-02 | 4.3 | CVE-2014-4547 MISC MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in pages/3DComplete.php in the WooCommerce SagePay Direct Payment Gateway plugin before 0.1.6.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MD or (2) PARes parameter. | 2014-07-02 | 4.3 | CVE-2014-4549 CONFIRM MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in diagnostics/test.php in the Social Connect plugin 1.0.4 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the testing parameter. | 2014-07-02 | 4.3 | CVE-2014-4551 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in library/includes/payment/ |
2014-07-02 | 4.3 | CVE-2014-4552 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in templates/download.php in the SS Downloads plugin before 1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title parameter. | 2014-07-02 | 4.3 | CVE-2014-4554 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in fonts/font-form.php in the Style It plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter. | 2014-07-02 | 4.3 | CVE-2014-4555 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for eShop plugin 3.7.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the api_url parameter. | 2014-07-01 | 4.3 | CVE-2014-4556 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in test-plugin.php in the Swipe Checkout for Jigoshop (swipe-hq-checkout-for- |
2014-07-02 | 4.3 | CVE-2014-4557 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in includes/getTipo.php in the ToolPage plugin 1.6.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the t parameter. | 2014-07-02 | 4.3 | CVE-2014-4560 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in go.php in the URL Cloak & Encrypt (url-cloak-encrypt) plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 2014-07-02 | 4.3 | CVE-2014-4563 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in check.php in the Validated plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter. | 2014-07-01 | 4.3 | CVE-2014-4564 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in vcc.js.php in the Verification Code for Comments plugin 2.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) vp, (2) vs, (3) l, (4) vu, or (5) vm parameter. | 2014-07-02 | 4.3 | CVE-2014-4565 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in res/fake_twitter/frame.php in the "verwei.se - WordPress - Twitter" (verweise-wordpress-twitter) plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the base parameter. | 2014-07-02 | 4.3 | CVE-2014-4566 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in posts/videowhisper/r_logout. |
2014-07-02 | 4.3 | CVE-2014-4568 MISC MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in ls/vv_login.php in the VideoWhisper Live Streaming Integration plugin 4.27.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the room_name parameter. | 2014-07-01 | 4.3 | CVE-2014-4569 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Video Presentation plugin before 3.31 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) room_name parameter to c_login.php or (2) room parameter to index.php in vp/. | 2014-07-02 | 4.3 | CVE-2014-4570 MISC MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in vncal.js.php in the VN-Calendar plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) fs or (2) w parameter. | 2014-07-02 | 4.3 | CVE-2014-4571 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in bvc.php in the Votecount for Balatarin plugin 0.1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the (1) url or (2) bvcurl parameter. | 2014-07-02 | 4.3 | CVE-2014-4572 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in frame-maker.php in the Walk Score plugin 0.5.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) o parameter. | 2014-07-02 | 4.3 | CVE-2014-4573 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in resize.php in the WebEngage plugin before 2.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the height parameter. | 2014-07-02 | 4.3 | CVE-2014-4574 MISC MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in js/window.php in the Wikipop plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter. | 2014-07-01 | 4.3 | CVE-2014-4575 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in services/diagnostics.php in the WordPress Social Login plugin 2.0.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the xhrurl parameter. | 2014-07-02 | 4.3 | CVE-2014-4576 |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in asset-studio/icons-launcher. |
2014-07-02 | 4.3 | CVE-2014-4578 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in js/test.php in the Appointments Scheduler plugin 1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | 2014-07-02 | 4.3 | CVE-2014-4579 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in blipbot.ajax.php in the WP BlipBot plugin 3.0.9 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the BlipBotID parameter. | 2014-07-02 | 4.3 | CVE-2014-4580 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in facture.php in the WPCB plugin 2.4.8 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter. | 2014-07-02 | 4.3 | CVE-2014-4581 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in admin/admin_show_dialogs.php in the WP Consultant plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the dialog_id parameter. | 2014-07-02 | 4.3 | CVE-2014-4582 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in forms/messages.php in the WP-Contact (wp-contact-sidebar-widget) plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) edit, (2) order_direction, (3) limit_start, (4) id, or (5) order parameter. | 2014-07-01 | 4.3 | CVE-2014-4583 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in admin/editFacility.php in the wp-easybooking plugin 1.0.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the fID parameter. | 2014-07-01 | 4.3 | CVE-2014-4584 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in the WP-FaceThumb plugin possibly 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the ajax_url parameter to index.php. | 2014-07-01 | 4.3 | CVE-2014-4585 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in the WP GuestMap plugin 1.8 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) zl, (2) mt, or (3) dc parameter to guest-locator.php; the (4) zl, (5) mt, (6) activate, or (7) dc parameter to online-tracker.php; the (8) zl, (9) mt, or (10) dc parameter to stats-map.php; or the (11) zl, (12) mt, (13) activate, or (14) dc parameter to weather-map.php. | 2014-07-02 | 4.3 | CVE-2014-4587 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in tpls/editmedia.php in the Hot Files: File Sharing and Download Manager (wphotfiles) plugin 1.0.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the mediaid parameter. | 2014-07-02 | 4.3 | CVE-2014-4588 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in uploader.php in the WP Silverlight Media Player (wp-media-player) plugin 0.8 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_id parameter. | 2014-07-02 | 4.3 | CVE-2014-4589 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in get.php in the WP Microblogs plugin 0.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the oauth_verifier parameter. | 2014-07-02 | 4.3 | CVE-2014-4590 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in picasa_upload.php in the WP-Picasa-Image plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_id parameter. | 2014-07-02 | 4.3 | CVE-2014-4591 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in wp-plugins-net/index.php in the WP Plugin Manager (wppm) plugin 1.6.4.b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filter parameter. | 2014-07-02 | 4.3 | CVE-2014-4593 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in index.php in the WordPress Responsive Preview plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter. | 2014-07-02 | 4.3 | CVE-2014-4594 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in the WP RESTful plugin 0.1 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) oauth_callback parameter to html_api_authorize.php or the (2) oauth_token_temp or (3) oauth_callback_temp parameter to html_api_login.php. | 2014-07-02 | 4.3 | CVE-2014-4595 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in js/button-snapapp.php in the SnapApp plugin 1.5 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) msg or (2) act parameter. | 2014-07-02 | 4.3 | CVE-2014-4596 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in test.php in the WP Social Invitations plugin before 1.4.4.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the xhrurl parameter. | 2014-07-02 | 4.3 | CVE-2014-4597 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in wp-tmkm-amazon-search.php in the wp-tmkm-amazon plugin 1.5b and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the AID parameter. | 2014-07-02 | 4.3 | CVE-2014-4598 CONFIRM MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in forms/search.php in the WP-Business Directory (wp-ttisbdir) plugin 1.0.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) edit, (2) search_term, (3) page_id, (4) page, or (5) page_links parameter. | 2014-07-02 | 4.3 | CVE-2014-4599 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in contact/edit.php in the WP Ultimate Email Marketer plugin 1.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) listname or (2) contact parameter. | 2014-07-02 | 4.3 | CVE-2014-4600 MISC MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in wu-ratepost.php in the Wu-Rating plugin 1.0 12319 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the v parameter. | 2014-07-02 | 4.3 | CVE-2014-4601 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in xencarousel-admin.js.php in the XEN Carousel plugin 0.12.2 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) path or (2) ajaxpath parameter. | 2014-07-01 | 4.3 | CVE-2014-4602 MISC |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter. | 2014-07-02 | 4.3 | CVE-2014-4603 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in settings/pwsettings.php in the Your Text Manager plugin 0.3.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the ytmpw parameter. | 2014-07-02 | 4.3 | CVE-2014-4604 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in cal/test.php in the ZdStatistics (zdstats) plugin 2.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | 2014-07-02 | 4.3 | CVE-2014-4605 MISC |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in redirect_to_zeenshare.php in the ZeenShare plugin 1.0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the zs_sid parameter. | 2014-07-02 | 4.3 | CVE-2014-4606 MISC |
N/A -- N/A | ** DISPUTED ** Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe. |
2014-07-03 | 5.0 | CVE-2014-4608 MISC CONFIRM CONFIRM MLIST MISC CONFIRM CONFIRM MISC |
N/A -- N/A | Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715. | 2014-07-03 | 5.0 | CVE-2014-4611 MISC MISC CONFIRM CONFIRM CONFIRM CONFIRM MLIST CONFIRM CONFIRM MISC MISC |
N/A -- N/A | Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrators for requests that use the (1) pwg.groups.addUser, (2) pwg.groups.deleteUser, (3) pwg.groups.setInfo, (4) pwg.users.setInfo, (5) pwg.permissions.add, or (6) pwg.permissions.remove method. | 2014-07-02 | 4.3 | CVE-2014-4614 MLIST CONFIRM |
N/A -- N/A | SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field. | 2014-06-28 | 6.5 | CVE-2014-4649 CONFIRM CONFIRM |
N/A -- N/A | Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access. | 2014-07-03 | 4.7 | CVE-2014-4652 CONFIRM CONFIRM MLIST CONFIRM CONFIRM |
N/A -- N/A | sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-after-free) and obtain sensitive information from kernel memory by leveraging /dev/snd/controlCX access. | 2014-07-03 | 6.6 | CVE-2014-4653 CONFIRM CONFIRM MLIST CONFIRM CONFIRM |
N/A -- N/A | The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, which allows local users to remove kernel controls and cause a denial of service (use-after-free and system crash) by leveraging /dev/snd/controlCX access for an ioctl call. | 2014-07-03 | 4.9 | CVE-2014-4654 CONFIRM CONFIRM MLIST CONFIRM CONFIRM |
N/A -- N/A | The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local users to cause a denial of service (integer overflow and limit bypass) by leveraging /dev/snd/controlCX access for a large number of SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl calls. | 2014-07-03 | 4.9 | CVE-2014-4655 CONFIRM CONFIRM MLIST CONFIRM CONFIRM |
N/A -- N/A | Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (1) index values in the snd_ctl_add function and (2) numid values in the snd_ctl_remove_numid_conflict function. | 2014-07-03 | 4.9 | CVE-2014-4656 CONFIRM CONFIRM CONFIRM MLIST CONFIRM CONFIRM CONFIRM |
N/A -- N/A | The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet. | 2014-07-03 | 5.0 | CVE-2014-4667 CONFIRM CONFIRM MLIST CONFIRM CONFIRM |
N/A -- N/A | The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password. | 2014-07-02 | 6.8 | CVE-2014-4668 CONFIRM MLIST MLIST |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the starttime0 parameter to firewall_schedule.php, (2) the rssfeed parameter to rss.widget.php, (3) the servicestatusfilter parameter to services_status.widget.php, (4) the txtRecallBuffer parameter to exec.php, or (5) the HTTP Referer header to log.widget.php. | 2014-07-02 | 4.3 | CVE-2014-4687 |
N/A -- N/A | pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias action, (2) the smartmonemail value to diag_smart.php, or (3) the database value to status_rrd_graph_img.php. | 2014-07-02 | 6.5 | CVE-2014-4688 |
N/A -- N/A | Absolute path traversal vulnerability in pkg_edit.php in pfSense before 2.1.4 allows remote attackers to read arbitrary XML files via a full pathname in the xml parameter. | 2014-07-02 | 5.0 | CVE-2014-4689 |
N/A -- N/A | Multiple directory traversal vulnerabilities in pfSense before 2.1.4 allow (1) remote attackers to read arbitrary .info files via a crafted path in the pkg parameter to pkg_mgr_install.php and allow (2) remote authenticated users to read arbitrary files via the downloadbackup parameter to system_firmware_ |
2014-07-02 | 5.0 | CVE-2014-4690 |
N/A -- N/A | Session fixation vulnerability in pfSense before 2.1.4 allows remote attackers to hijack web sessions via a firewall login cookie. | 2014-07-02 | 6.8 | CVE-2014-4691 |
N/A -- N/A | pfSense before 2.1.4, when HTTP is used, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | 2014-07-02 | 4.3 | CVE-2014-4692 |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the eng parameter to snort_import_aliases.php or (2) unspecified variables to snort_select_alias.php. | 2014-07-02 | 4.3 | CVE-2014-4693 |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in suricata_select_alias.php in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via unspecified variables. | 2014-07-02 | 4.3 | CVE-2014-4694 |
N/A -- N/A | Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to snort_rules_flowbits.php or (2) the returl parameter to snort_select_alias.php. | 2014-07-02 | 5.8 | CVE-2014-4695 |
N/A -- N/A | Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to suricata_rules_flowbits.php or (2) the returl parameter to suricata_select_alias.php. | 2014-07-02 | 5.8 | CVE-2014-4696 |
N/A -- N/A | Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run, a different vulnerability than CVE-2014-4611. | 2014-07-03 | 5.0 | CVE-2014-4715 CONFIRM CONFIRM CONFIRM MISC |
Low Vulnerabilities
Primary Vendor -- Product |
Description | Published | CVSS Score | Source & Patch Info |
---|---|---|---|---|
N/A -- N/A | Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.x and 7.2.x before 7.2.1.5 allows remote authenticated users to read arbitrary files via unspecified vectors. | 2014-07-01 | 3.5 | CVE-2013-3004 XF |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 2014-06-27 | 3.5 | CVE-2013-6310 XF |
N/A -- N/A | iBooks Commerce in Apple OS X before 10.9.4 places Apple ID credentials in the iBooks log, which allows local users to obtain sensitive information by reading this file. | 2014-07-01 | 2.1 | CVE-2014-1317 APPLE |
N/A -- N/A | Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mounting the data partition. | 2014-07-01 | 2.1 | CVE-2014-1348 BID MISC APPLE |
N/A -- N/A | Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously. | 2014-07-01 | 3.6 | CVE-2014-1351 APPLE |
N/A -- N/A | Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct brute-force passcode-guessing attacks via unspecified vectors. | 2014-07-01 | 1.9 | CVE-2014-1352 APPLE |
N/A -- N/A | Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode, which allows physically proximate attackers to bypass the lock protection mechanism, and access a certain foreground application, via unspecified vectors. | 2014-07-01 | 3.6 | CVE-2014-1353 APPLE |
N/A -- N/A | Lockdown in Apple iOS before 7.1.2 does not properly verify data from activation servers, which makes it easier for physically proximate attackers to bypass the Activation Lock protection mechanism via unspecified vectors. | 2014-07-01 | 2.1 | CVE-2014-1360 APPLE |
N/A -- N/A | Intel Graphics Driver in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object. | 2014-07-01 | 2.1 | CVE-2014-1375 APPLE |
N/A -- N/A | IOGraphicsFamily in Apple OS X before 10.9.4 allows local users to bypass the ASLR protection mechanism by leveraging read access to a kernel pointer in an IOKit object. | 2014-07-01 | 2.1 | CVE-2014-1378 APPLE |
N/A -- N/A | The Security - Keychain component in Apple OS X before 10.9.4 does not properly implement keystroke observers, which allows physically proximate attackers to bypass the screen-lock protection mechanism, and enter characters into an arbitrary window under the lock window, via keyboard input. | 2014-07-01 | 2.6 | CVE-2014-1380 APPLE |
N/A -- N/A | Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom 7.4.3, 7.4.4 before P19, and 7.4.4 SP1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 2014-06-30 | 3.5 | CVE-2014-2512 BUGTRAQ |
N/A -- N/A | The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct a side-channel attack via a D-Bus message to an inactive service. | 2014-07-01 | 2.1 | CVE-2014-3477 CONFIRM BID |
N/A -- N/A | Cross-site scripting (XSS) vulnerability in templates/defaultheader.php in Lamp Design Storesprite before 7 - 19-06-14, when using the currency selection dropdown, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to brand.php, related to the currencyUrl function. | 2014-07-02 | 2.6 | CVE-2014-3737 MISC BID BUGTRAQ SECUNIA MISC |
N/A -- N/A | HP Enterprise Maps 1.00 allows remote authenticated users to read arbitrary files via a WSDL document containing an XML external entity declaration in conjunction with an entity reference within a GetQuote operation, related to an XML External Entity (XXE) issue. | 2014-06-28 | 3.5 | CVE-2014-4669 MISC |
원본기사확인하기: [US-CERT: Bulletin(SB14-188)] 2014년 6월 30일까지 발표된 보안 취약점