CVE Database - 2014

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

2733
Matching CVEs
16133
Critical
35026
High
84348
High WAF Coverage

CVE-2014-7241

MEDIUM
6.80 CVSS 2.0

The TSUTAYA application 5.3 and earlier for Android allows remote attackers to execute arbitrary Java methods via a crafted HTML document.

Improper Input Validation
WAF: Medium

CVE-2014-8902

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Blog Portlet in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-6173

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Process Inspector in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-6171

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF14, and 8.5.0 before CF04 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-4801

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4, 4.x before 4.0.7 iFix 2, and 5.x before 5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-8012

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the WebVPN Portal Login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via crafted attributes in a cookie, aka Bug ID CSCuh24695.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-6167

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-6080

MEDIUM
6.50 CVSS 2.0

SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2014-6077

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2014-9253

MEDIUM
4.30 CVSS 2.0

The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF file, then accessing it via the media parameter to lib/exe/fetch.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-5438

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-5437

MEDIUM
6.80 CVSS 2.0

Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php, (2) add a port forwarding rule via a request to port_forwarding_add.php, (3) change the wireless network to open via a request to wireless_network_configuration_edit.php, or (4) conduct cross-site scripting (XSS) attacks via the keyword parameter to managed_sites_add_keyword.php.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2014-7285

MEDIUM
6.50 CVSS 2.0

The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Command Injection
WAF: High

CVE-2014-9322

HIGH
7.80 CVSS 3.1

arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.

Improper Privilege Management
WAF: Low

CVE-2014-8006

MEDIUM
4.30 CVSS 2.0

The Disaster Recovery (DRA) feature on the Cisco ISB8320-E High-Definition IP-Only DVR allows remote attackers to bypass authentication by establishing a TELNET session during a recovery boot, aka Bug ID CSCup85422.

Improper Authentication
WAF: Low

CVE-2014-6182

MEDIUM
4.00 CVSS 2.0

Directory traversal vulnerability in an export function in the Process Center in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3 and 8.5.x through 8.5.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.

Path Traversal
WAF: High

CVE-2014-8248

MEDIUM
6.50 CVSS 2.0

SQL injection vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote authenticated users to execute arbitrary SQL commands via a crafted query.

SQL Injection
WAF: High

CVE-2014-8247

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-8246

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2014-9373

HIGH
10.00 CVSS 2.0

Directory traversal vulnerability in the CollectorConfInfoServlet servlet in ManageEngine NetFlow Analyzer allows remote attackers to execute arbitrary code via a .. (dot dot) in the filename.

Path Traversal
WAF: High

CVE-2014-9372

MEDIUM
6.40 CVSS 2.0

Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename.

Path Traversal
WAF: High

CVE-2014-9371

HIGH
10.00 CVSS 2.0

The NativeAppServlet in ManageEngine Desktop Central MSP before 90075 allows remote attackers to execute arbitrary code via a crafted JSON object.

Improper Input Validation
WAF: Medium

CVE-2014-9358

MEDIUM
6.40 CVSS 2.0

Docker before 1.3.3 does not properly validate image IDs, which allows remote attackers to conduct path traversal attacks and spoof repositories via a crafted image in a (1) "docker load" operation or (2) "registry communications."

Improper Input Validation
WAF: Medium

CVE-2014-9057

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2014-8751

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in goYWP WebPress 13.00.06 allow remote attackers to inject arbitrary web script or HTML via the (1) search_param parameter to search.php or (2) name, (3) address, or (4) comment parameter to forms.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-8340

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in Php/Functions/log_function.php in phpTrafficA 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via a User-Agent HTTP header.

SQL Injection
WAF: High

CVE-2014-5466

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.7, and 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-5359

HIGH
7.80 CVSS 2.0

Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard) before 1.03.30109 allows remote attackers to read arbitrary files via a .. (dot dot) in the GetFile parameter to owa/owa.

Path Traversal
WAF: High

CVE-2014-9385

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in Zenoss Core through 5 Beta 3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger arbitrary code execution via a ZenPack upload, aka ZEN-15388.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2014-8507

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in the queryLastApp method in packages/WAPPushManager/src/com/android/smspush/WapPushManager.java in the WAPPushManager module in Android before 5.0.0 allow remote attackers to execute arbitrary SQL commands, and consequently launch an activity or service, via the (1) wapAppId or (2) contentType field of a PDU for a malformed WAPPush message, aka Bug 17969135.

SQL Injection
WAF: High

CVE-2014-6261

HIGH
9.30 CVSS 2.0

Zenoss Core through 5 Beta 3 does not properly implement the Check For Updates feature, which allows remote attackers to execute arbitrary code by (1) spoofing the callhome server or (2) deploying a crafted web site that is visited during a login session, aka ZEN-12657.

Code Injection
WAF: Medium

CVE-2014-6260

MEDIUM
6.80 CVSS 2.0

Zenoss Core through 5 Beta 3 does not require a password for modifying the pager command string, which allows remote attackers to execute arbitrary commands or cause a denial of service (paging outage) by leveraging an unattended workstation, aka ZEN-15412.

Command Injection
WAF: High

CVE-2014-6254

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arbitrary web script or HTML via an attribute in a (1) device name, (2) device detail, (3) report name, (4) report detail, or (5) portlet name, or (6) a string to a helper method, aka ZEN-15381 and ZEN-15410.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-6253

MEDIUM
6.80 CVSS 2.0

Multiple cross-site request forgery (CSRF) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to hijack the authentication of arbitrary users, aka ZEN-12653.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2014-6052

HIGH
7.50 CVSS 2.0

The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitrary code by specifying a large screen size in a (1) FramebufferUpdate, (2) ResizeFrameBuffer, or (3) PalmVNCReSizeFrameBuffer message.

Improper Input Validation
WAF: Medium

CVE-2014-3364

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard parameter, aka Bug ID CSCuq80661.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-4633

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-4628

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in EMC Isilon InsightIQ 2.x and 3.x before 3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-6210

MEDIUM
4.00 CVSS 2.0

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying the same column within multiple ALTER TABLE statements.

Improper Input Validation
WAF: Medium

CVE-2014-6209

MEDIUM
4.00 CVSS 2.0

IBM DB2 9.5 through FP10, 9.7 through FP10, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) by specifying an identity column within a crafted ALTER TABLE statement.

Improper Input Validation
WAF: Medium

CVE-2014-8515

MEDIUM
6.80 CVSS 2.0

The web interface in BitTorrent allows remote attackers to execute arbitrary commands by leveraging knowledge of the pairing values and a crafted request to port 10000.

Command Injection
WAF: High

CVE-2014-8124

MEDIUM
5.00 CVSS 2.0

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.

Uncontrolled Resource Consumption
WAF: Medium

CVE-2014-7840

HIGH
7.50 CVSS 2.0

The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.

Improper Input Validation
WAF: Medium

CVE-2014-6381

LOW
2.90 CVSS 2.0

Juniper WLC devices with WLAN Software releases 8.0.x before 8.0.4, 9.0.x before 9.0.2.11, 9.0.3.x before 9.0.3.5, and 9.1.x before 9.1.1, when "Proxy ARP" or "No Broadcast" features are enabled in a clustered setup, allows remote attackers to cause a denial of service (device disconnect) via unspecified vectors.

Improper Input Validation
WAF: Medium

CVE-2014-7265

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in LinPHA allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-6145

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence 10.1 before IF10, 10.1.1 before IF9, 10.2 before IF11, 10.2.1 before IF8, and 10.2.1.1 before IF7 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-4323

HIGH
7.50 CVSS 2.0

The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain start and length values within an ioctl call, which allows attackers to gain privileges via a crafted application.

Improper Input Validation
WAF: Medium

CVE-2014-7263

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP header, a different vulnerability than CVE-2014-7261.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-7262

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Omake BBS component in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string.

Cross-Site Scripting (XSS)
WAF: High

CVE-2014-7261

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in ULTRAPOP.JP i-HTTPD allows remote attackers to inject arbitrary web script or HTML via a crafted string that is improperly rendered during construction of a directory index page, a different vulnerability than CVE-2014-7263.

Cross-Site Scripting (XSS)
WAF: High
Page 3 of 55 (2733 CVEs)