LiveActive security incident?Get immediate response
CVE archive

December 2014

Browse CVE records published in December 2014, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 626 matching CVEs · Page 4 of 13.

Unknown · CVSS Not scored

CVE-2014-9215: SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 bef...

SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128 allows remote attackers to execute arbitrary SQL commands via the email parameter in the register page to index.php. NOTE: the email parameter in the forget page vector is already covered by CVE-2012-4034.2.

Published Dec 5, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-9158: Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to...

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-8445, CVE-2014-8446, CVE-2014-8447, CVE-2014-8456, CVE-2014-8458, CVE-2014-8459, and CVE-2014-8461.

Published Dec 10, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-9178: Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Documen...

Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plugin (sp-client-document-manager) 2.4.1 and earlier for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) vendor_email[] parameter in the email_vendor function or id parameter in the (2) download_project, (3) download_archive, or (4) remove_cat function.

Published Dec 2, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-9115: SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before...

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.

Published Dec 23, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-9066: Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, w...

Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.

Published Dec 9, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-9129: Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0...

Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page to wp-admin/admin.php.

Published Dec 5, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-9113: CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Auth...

CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.

Published Dec 2, 2014 · Updated Aug 6, 2024