LiveActive security incident?Get immediate response
CVE archive

July 2014

Browse CVE records published in July 2014, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 698 matching CVEs · Page 10 of 14.

Unknown · CVSS Not scored

CVE-2014-3320: Multiple open redirect vulnerabilities in the admin web interface in the web framework in Cisco Unified Com...

Multiple open redirect vulnerabilities in the admin web interface in the web framework in Cisco Unified Communications Domain Manager (CDM) 8.1(.4) and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted URLs for unspecified scripts, aka Bug ID CSCuo48835.

Published Jul 18, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-3297: Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MySe...

Cisco Intelligent Automation for Cloud in Cisco Cloud Portal does not properly restrict the content of MyServices action URLs, which allows remote authenticated users to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug IDs CSCui36937, CSCui37004, and CSCui36927.

Published Jul 2, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-3161: The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Goo...

The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly interact with redirects, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that hosts a video stream.

Published Jul 20, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-3159: The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_con...

The WebContentsDelegateAndroid::OpenURLFromTab function in components/web_contents_delegate_android/web_contents_delegate_android.cc in Google Chrome before 36.0.1985.122 on Android does not properly restrict URL loading, which allows remote attackers to spoof the URL in the Omnibox via unspecified vectors.

Published Jul 20, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-3149: Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4....

Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.3.x and 3.4.x through 3.4.6, as downloaded before 20140424, or IP.Nexus 1.5.x through 1.5.9, as downloaded before 20140424, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published Jul 3, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-3088: stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wA...

stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST requests, which allows remote authenticated users to bypass intended upload restrictions by modifying the Content-Type header and file extension, as demonstrated by replacing a text/plain .txt upload with an application/octet-stream .exe upload.

Published Jul 1, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-3025: Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x a...

Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.2, and 7.2 for Tivoli Asset Management for IT and certain other products allow remote authenticated users to inject arbitrary web script or HTML via unspecified input to a .jsp file under webclient/utility/.

Published Jul 30, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-2969: NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for...

NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser account, which allows remote attackers to upload firmware or read or modify memory contents, and consequently execute arbitrary code, via a request to (1) produce_burn.cgi, (2) register_debug.cgi, or (3) bootcode_update.cgi.

Published Jul 7, 2014 · Updated Aug 6, 2024