LiveActive security incident?Get immediate response
CVE archive

December 2014

Browse CVE records published in December 2014, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 626 matching CVEs · Page 9 of 13.

Unknown · CVSS Not scored

CVE-2014-6355: The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and...

The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly process JPEG images, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Graphics Component Information Disclosure Vulnerability."

Published Dec 11, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-6357: Use-after-free vulnerability in Microsoft Office 2010 SP2, Office 2013 Gold and SP1, Office 2013 RT Gold an...

Use-after-free vulnerability in Microsoft Office 2010 SP2, Office 2013 Gold and SP1, Office 2013 RT Gold and SP1, Office for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 Gold and SP1, and Office Web Apps 2010 SP2 and 2013 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Use After Free Word Remote Code Execution Vulnerability."

Published Dec 11, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-6336: Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly valid...

Outlook Web App (OWA) in Microsoft Exchange Server 2013 SP1 and Cumulative Update 6 does not properly validate redirection tokens, which allows remote attackers to redirect users to arbitrary web sites and spoof the origin of e-mail messages via unspecified vectors, aka "Exchange URL Redirection Vulnerability."

Published Dec 11, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-6228: Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop...

Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted arguments to the chunk_split function.

Published Dec 28, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-6254: Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers...

Multiple cross-site scripting (XSS) vulnerabilities in Zenoss Core through 5 Beta 3 allow remote attackers to inject arbitrary web script or HTML via an attribute in a (1) device name, (2) device detail, (3) report name, (4) report detail, or (5) portlet name, or (6) a string to a helper method, aka ZEN-15381 and ZEN-15410.

Published Dec 15, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-6259: Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remot...

Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka ZEN-15414, a similar issue to CVE-2003-1564.

Published Dec 15, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-6176: IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanc...

IBM WebSphere Process Server 7.0, WebSphere Enterprise Service Bus 7.0, and Business Process Manager Advanced 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 disregard the SSL setting in the SCA module HTTP import binding and unconditionally select the SSLv3 protocol, which makes it easier for remote attackers to hijack sessions or obtain sensitive information by leveraging the use of a weak cipher.

Published Dec 16, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2014-6166: The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0....

The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Published Dec 18, 2014 · Updated Aug 6, 2024