LiveActive security incident?Get immediate response
CVE archive

January 2014

Browse CVE records published in January 2014, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 45 of 895 matching CVEs · Page 18 of 18.

Unknown · CVSS Not scored

CVE-2014-0405: Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior t...

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0407.

Published Jan 15, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-0260: Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word...

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

Published Jan 15, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-0245: It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thre...

It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take long to execute, it was possible for an unauthenticated remote attacker to gain privileged information if WS-Security is enabled for the WSRP Consumer, and the endpoint in question is being used by a privileged user. This affects JBoss Portal 6.2.0.

Published Jan 2, 2020 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-0191: The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Ora...

The xmlParserHandlePEReference function in parser.c in libxml2 before 2.9.2, as used in Web Listener in Oracle HTTP Server in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 and other products, loads external parameter entities regardless of whether entity substitution or validation is enabled, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document.

Published Jan 21, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-0169: In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that...

In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resources in another application without proper authorization. Although this is an intended functionality, it was not clearly documented which can mislead users into thinking that a security domain cache is isolated to a single application.

Published Jan 2, 2020 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-0161: ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint...

ovirt-engine-sdk-python before 3.4.0.7 and 3.5.0.4 does not verify that the hostname of the remote endpoint matches the Common Name (CN) or subjectAltName as specified by its x.509 certificate in a TLS/SSL session. This could allow man-in-the-middle attackers to spoof remote endpoints via an arbitrary valid certificate.

Published Jan 2, 2020 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-0028: libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:sea...

libvirt 1.1.1 through 1.2.0 allows context-dependent attackers to bypass the domain:getattr and connect:search_domains restrictions in ACLs and obtain sensitive domain object information via a request to the (1) virConnectDomainEventRegister and (2) virConnectDomainEventRegisterAny functions in the event registration API.

Published Jan 24, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-0010: Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2....

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.

Published Jan 20, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-0009: course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, a...

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.

Published Jan 20, 2014 · Updated Aug 6, 2024