LiveActive security incident?Get immediate response
CVE archive

June 2014

Browse CVE records published in June 2014, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 470 matching CVEs · Page 4 of 10.

Unknown · CVSS Not scored

CVE-2014-4506: Cross-site scripting (XSS) vulnerability in the Custom Meta module 6.x-1.x before 6.x-1.2 and 7.x-1.x befor...

Cross-site scripting (XSS) vulnerability in the Custom Meta module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "administer custom meta settings" permission to inject arbitrary web script or HTML via the (1) attribute or (2) content value for a meta tag.

Published Jun 20, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-4301: Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene P...

Multiple cross-site scripting (XSS) vulnerabilities in the respond_error function in routing.py in Eugene Pankov Ajenti before 1.2.21.7 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) resources.js or (2) resources.css in ajenti:static/, related to the traceback page.

Published Jun 18, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-4193: The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random ext...

The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algorithm, which makes it easier for remote attackers to obtain plaintext from TLS sessions by requesting long nonces from a server, a different issue than CVE-2007-6755.

Published Jun 17, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-4171: mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range not...

mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.

Published Jun 23, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-4157: arch/mips/include/asm/thread_info.h in the Linux kernel before 3.14.8 on the MIPS platform does not configu...

arch/mips/include/asm/thread_info.h in the Linux kernel before 3.14.8 on the MIPS platform does not configure _TIF_SECCOMP checks on the fast system-call path, which allows local users to bypass intended PR_SET_SECCOMP restrictions by executing a crafted application without invoking a trace or audit subsystem.

Published Jun 23, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-4047: Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Aster...

Asterisk Open Source 1.8.x before 1.8.28.1, 11.x before 11.10.1, and 12.x before 12.3.1 and Certified Asterisk 1.8.15 before 1.8.15-cert6 and 11.6 before 11.6-cert3 allows remote attackers to cause a denial of service (connection consumption) via a large number of (1) inactive or (2) incomplete HTTP connections.

Published Jun 17, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-4037: Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spel...

Cross-site scripting (XSS) vulnerability in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor before 2.6.11 and earlier allows remote attackers to inject arbitrary web script or HTML via an array key in the textinputs[] parameter, a different issue than CVE-2012-4000.

Published Jun 11, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-4014: The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespace...

The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.

Published Jun 23, 2014 · Updated Aug 6, 2024