Vulnerabilities (CVE)

Total 395957 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-3453 1 Flag Module Project 1 Flag 2026-06-17 6.5 MEDIUM N/A
Eval injection vulnerability in the flag_import_form_validate function in includes/flag.export.inc in the Flag module 7.x-3.0, 7.x-3.5, and earlier for Drupal allows remote authenticated administrators to execute arbitrary PHP code via the "Flag import code" text area to admin/structure/flags/import. NOTE: this issue could also be exploited by other attackers if the administrator ignores a security warning on the permissions assignment page.
CVE-2014-3452 1 Codecguide 1 K-lite Codec Pack 2026-06-17 4.3 MEDIUM N/A
Filters\LAV\avfilter-lav-4.dll in K-lite Codec 10.4.5 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .jpg file.
CVE-2014-3451 1 Igniterealtime 1 Openfire 2026-06-17 5.0 MEDIUM 7.5 HIGH
OpenFire XMPP Server before 3.10 accepts self-signed certificates, which allows remote attackers to perform unspecified spoofing attacks.
CVE-2014-3450 1 Pandasecurity 4 Panda Av Pro 2014, Panda Global Protection 2014, Panda Gold Protection and 1 more 2026-06-17 7.2 HIGH N/A
Unspecified vulnerability in Panda Gold Protection and Global Protection 2014 7.01.01 and earlier, Internet Security 2014 19.01.01 and earlier, and AV Pro 2014 13.01.01 and earlier allows local users to gain privileges via unspecified vectors.
CVE-2014-3449 1 Bss Continuity Cms Project 1 Bss Continuty Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
BSS Continuity CMS 4.2.22640.0 has an Authentication Bypass vulnerability
CVE-2014-3448 1 Bss Continuity Cms Project 1 Bss Continuty Cms 2026-06-17 7.5 HIGH 9.8 CRITICAL
BSS Continuity CMS 4.2.22640.0 has a Remote Code Execution vulnerability due to unauthenticated file upload
CVE-2014-3447 1 Bss Continuity Cms Project 1 Bss Continuty Cms 2026-06-17 5.0 MEDIUM 7.5 HIGH
BSS Continuity CMS 4.2.22640.0 has a Remote Denial Of Service vulnerability
CVE-2014-3446 1 Bss 1 Continuity Cms 2026-06-17 7.5 HIGH N/A
SQL injection vulnerability in wcm/system/pages/admin/getnode.aspx in BSS Continuity CMS 4.2.22640.0 allows remote attackers to execute arbitrary SQL commands via the nodeid parameter.
CVE-2014-3445 1 Handsomeweb 1 Sos Webpages 2026-06-17 7.5 HIGH 9.8 CRITICAL
backup.php in HandsomeWeb SOS Webpages before 1.1.12 does not require knowledge of the cleartext password, which allows remote attackers to bypass authentication by leveraging knowledge of the administrator password hash.
CVE-2014-3444 1 Realnetworks 1 Realplayer 2026-06-17 9.3 HIGH N/A
The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.
CVE-2014-3443 1 Jetaudio 1 Jetaudio 2026-06-17 4.3 MEDIUM N/A
JetMPAd.ax in JetAudio 8.1.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file.
CVE-2014-3442 1 Nullsoft 1 Winamp 2026-06-17 4.3 MEDIUM N/A
Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malformed .FLV file, related to f263.w5s.
CVE-2014-3441 1 Videolan 1 Vlc Media Player 2026-06-17 4.3 MEDIUM N/A
codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as demonstrated by a png in a .wave file.
CVE-2014-3440 2 Broadcom, Symantec 2 Symantec Critical System Protection, Data Center Security 2026-06-17 9.0 HIGH N/A
The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.0.x before 6.0 MP1 allows remote authenticated users to execute arbitrary commands by leveraging client-system access to upload a log file.
CVE-2014-3439 1 Symantec 1 Endpoint Protection Manager 2026-06-17 6.1 MEDIUM N/A
ConsoleServlet in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to write to arbitrary files via unspecified vectors.
CVE-2014-3438 1 Symantec 1 Endpoint Protection Manager 2026-06-17 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in console interface scripts in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2014-3437 1 Symantec 1 Endpoint Protection Manager 2026-06-17 7.5 HIGH N/A
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU5 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVE-2014-3436 1 Symantec 2 Encryption Desktop, Pgp Desktop 2026-06-17 5.0 MEDIUM N/A
Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted encrypted e-mail message that decompresses to a larger size.
CVE-2014-3434 1 Symantec 1 Endpoint Protection 2026-06-17 6.9 MEDIUM N/A
Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition before SEP 12.1, allows local users to execute arbitrary code via a long argument to a 0x00222084 IOCTL call.
CVE-2014-3433 1 Symantec 1 Data Insight 2026-06-17 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the management console in Symantec Data Insight 3.x and 4.x before 4.5 allows remote attackers to inject arbitrary web script or HTML via an unspecified form field, related to an "HTML script injection" issue.