Total
29929 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2014-5396 | 1 Schrack | 2 Technik Microcontrol, Technik Microcontrol Firmware | 2026-06-17 | 7.5 HIGH | N/A |
| The web interface in Schrack Technik microControl with firmware before 1.7.0 (937) has a hardcoded password of not for the "user" account, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
| CVE-2014-5392 | 1 Sos | 1 Jobscheduler | 2026-06-17 | 5.8 MEDIUM | N/A |
| XML External Entity (XXE) vulnerability in JobScheduler before 1.6.4246 and 7.x before 1.7.4241 allows remote attackers to cause a denial of service and read arbitrary files or directories via a request containing an XML external entity declaration in conjunction with an entity reference. | |||||
| CVE-2014-5355 | 1 Mit | 1 Kerberos 5 | 2026-06-17 | 5.0 MEDIUM | N/A |
| MIT Kerberos 5 (aka krb5) through 1.13.1 incorrectly expects that a krb5_read_message data field is represented as a string ending with a '\0' character, which allows remote attackers to (1) cause a denial of service (NULL pointer dereference) via a zero-byte version string or (2) cause a denial of service (out-of-bounds read) by omitting the '\0' character, related to appl/user_user/server.c and lib/krb5/krb/recvauth.c. | |||||
| CVE-2014-5354 | 1 Mit | 2 Kerberos, Kerberos 5 | 2026-06-17 | 3.5 LOW | N/A |
| plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by creating a database entry for a keyless principal, as demonstrated by a kadmin "add_principal -nokey" or "purgekeys -all" command. | |||||
| CVE-2014-5352 | 1 Mit | 1 Kerberos 5 | 2026-06-17 | 9.0 HIGH | N/A |
| The krb5_gss_process_context_token function in lib/gssapi/krb5/process_context_token.c in the libgssapi_krb5 library in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 does not properly maintain security-context handles, which allows remote authenticated users to cause a denial of service (use-after-free and double free, and daemon crash) or possibly execute arbitrary code via crafted GSSAPI traffic, as demonstrated by traffic to kadmind. | |||||
| CVE-2014-5237 | 1 Open-xchange | 1 App Suite | 2026-06-17 | 4.3 MEDIUM | N/A |
| Server-side request forgery (SSRF) vulnerability in the documentconverter component in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allows remote attackers to trigger requests to arbitrary servers and embed arbitrary images via a URL in an embedded image in a Text document, which is not properly handled by the image preview. | |||||
| CVE-2014-5214 | 1 Microfocus | 1 Access Manager | 2026-06-17 | 4.0 MEDIUM | N/A |
| nps/servlet/webacc in iManager in the Administration Console server in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allows remote authenticated novlwww users to read arbitrary files via a query parameter containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |||||
| CVE-2014-5176 | 1 Sap | 1 Fi Manager Self-service | 2026-06-17 | 6.0 MEDIUM | N/A |
| SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
| CVE-2014-5139 | 1 Openssl | 1 Openssl | 2026-06-17 | 4.3 MEDIUM | N/A |
| The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client. | |||||
| CVE-2014-5138 | 1 Iii | 1 Sierra | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instances of the same parameter, which allows remote attackers to bypass parameter validation via unspecified vectors, possibly related to the Webpac Pro submodule. | |||||
| CVE-2014-5127 | 1 Iii | 1 Encore Discovery Solution | 2026-06-17 | 5.8 MEDIUM | N/A |
| Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter. | |||||
| CVE-2014-5122 | 1 Esri | 1 Arcgis Server | 2026-06-17 | 5.8 MEDIUM | N/A |
| Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, related to login. | |||||
| CVE-2014-5117 | 1 Torproject | 1 Tor | 2026-06-17 | 5.8 MEDIUM | N/A |
| Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAY_EARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the pattern of RELAY and RELAY_EARLY cells as a means of communicating information about hidden service names. | |||||
| CVE-2014-5116 | 1 Cairographics | 1 Cairo | 2026-06-17 | 5.0 MEDIUM | N/A |
| The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string. | |||||
| CVE-2014-5114 | 1 Webidsupport | 1 Webid | 2026-06-17 | 7.5 HIGH | N/A |
| WeBid 1.1.1 allows remote attackers to conduct an LDAP injection attack via the (1) js or (2) cat parameter. | |||||
| CVE-2014-5073 | 1 Vmturbo | 1 Operations Manager | 2026-06-17 | 7.5 HIGH | N/A |
| vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call. | |||||
| CVE-2014-5035 | 1 Opendaylight | 1 Opendaylight | 2026-06-17 | 6.8 MEDIUM | N/A |
| The Netconf (TCP) service in OpenDaylight 1.0 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference in an XML-RPC message, related to an XML External Entity (XXE) issue. | |||||
| CVE-2014-5023 | 1 Gitlist | 1 Gitlist | 2026-06-17 | 6.8 MEDIUM | N/A |
| Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command. | |||||
| CVE-2014-5018 | 1 Limesurvey | 1 Limesurvey | 2026-06-17 | 4.3 MEDIUM | N/A |
| Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume. | |||||
| CVE-2014-4851 | 1 Foecms | 1 Foecms | 2026-06-17 | 5.8 MEDIUM | N/A |
| Open redirect vulnerability in msg.php in FoeCMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the r parameter. | |||||
