LiveActive security incident?Get immediate response
CVE archive

March 2014

Browse CVE records published in March 2014, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 531 matching CVEs · Page 6 of 11.

Unknown · CVSS Not scored

CVE-2014-2243: includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 te...

includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which makes it easier for remote attackers to obtain access via a brute-force attack that relies on timing differences in responses to incorrect token guesses.

Published Mar 2, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2250: The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not ha...

The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors, a different vulnerability than CVE-2014-2251.

Published Mar 22, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2244: Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in Me...

Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows remote attackers to inject arbitrary web script or HTML via a crafted string located after http:// in the text parameter to api.php.

Published Mar 2, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2291: Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper...

Cross-site scripting (XSS) vulnerability in the Pulse Collaboration (Secure Meeting) user pages in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r18, 7.3 before 7.3r10, 7.4 before 7.4r8, and 8.0 before 8.0r1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Published Mar 14, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2234: A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feat...

A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL handshakes as specified in the SSL_CTX_set_verify callback function's documentation, which allows remote attackers to bypass extra verification within a custom application via a crafted certificate chain that is acceptable to TEA but not acceptable to that application.

Published Mar 5, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2274: Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219...

Cross-site request forgery (CSRF) vulnerability in the Subscribe To Comments Reloaded plugin before 140219 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via a request to the subscribe-to-comments-reloaded/options/index.php page to wp-admin/admin.php.

Published Mar 19, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2281: The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8....

The nfs_name_snoop_add_name function in epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.8.x before 1.8.13 and 1.10.x before 1.10.6 does not validate a certain length value, which allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted NFS packet.

Published Mar 11, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2245: SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote auth...

SQL injection vulnerability in the News module in CMS Made Simple (CMSMS) before 1.11.10 allows remote authenticated users with the "Modify News" permission to execute arbitrary SQL commands via the sortby parameter to admin/moduleinterface.php. NOTE: some of these details are obtained from third party information.

Published Mar 5, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2119: The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (...

The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1-023 and Cisco Content Security Management Appliance (SMA) before 7.9.1-110 and 8.x before 8.1.1-013 allows remote authenticated users to execute arbitrary code with root privileges via an FTP session that uploads a modified SLBL database file, aka Bug IDs CSCug79377 and CSCug80118.

Published Mar 20, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2130: Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Ap...

Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka Bug ID CSCuj83189.

Published Mar 6, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2097: The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a ce...

The tak_decode_frame function in libavcodec/takdec.c in FFmpeg before 2.1.4 does not properly validate a certain bits-per-sample value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted TAK (aka Tom's lossless Audio Kompressor) data.

Published Mar 2, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2104: Multiple cross-site scripting (XSS) vulnerabilities in the Business Voice Services Manager (BVSM) page in C...

Multiple cross-site scripting (XSS) vulnerabilities in the Business Voice Services Manager (BVSM) page in Cisco Unified Communications Domain Manager 9.0(.1) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCum78536, CSCum78526, CSCum69809, and CSCum63113.

Published Mar 2, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2091: Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allow...

Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the title parameter in an add_forum action. NOTE: the original disclosure also reported issues that may not cross privilege boundaries.

Published Mar 2, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2092: Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple...

Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action parameter, a different issue than CVE-2014-0334. NOTE: the original disclosure also reported issues that may not cross privilege boundaries.

Published Mar 2, 2014 · Updated Aug 6, 2024