Vulnerabilities (CVE)

Total 395814 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-125009 1 Ffmpeg 1 Ffmpeg 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
A vulnerability classified as problematic has been found in FFmpeg 2.0. This affects the function add_yblock of the file libavcodec/snow.h. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125008 1 Ffmpeg 1 Ffmpeg 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
A vulnerability classified as problematic has been found in FFmpeg 2.0. Affected is the function vorbis_header of the file libavformat/oggparsevorbis.c. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125007 1 Ffmpeg 1 Ffmpeg 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
A vulnerability classified as problematic was found in FFmpeg 2.0. Affected by this vulnerability is the function intra_pred of the file libavcodec/hevcpred_template.c. The manipulation leads to memory corruption. The attack can be launched remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125006 1 Ffmpeg 1 Ffmpeg 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
A vulnerability, which was classified as problematic, has been found in FFmpeg 2.0. Affected by this issue is the function output_frame of the file libavcodec/h264.c. The manipulation leads to memory corruption. The attack may be launched remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125005 1 Ffmpeg 1 Ffmpeg 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
A vulnerability, which was classified as problematic, was found in FFmpeg 2.0. This affects the function decode_vol_header of the file libavcodec/mpeg4videodec.c. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125004 1 Ffmpeg 1 Ffmpeg 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
A vulnerability has been found in FFmpeg 2.0 and classified as problematic. This vulnerability affects the function decode_hextile of the file libavcodec/vmnc.c. The manipulation leads to memory corruption. The attack can be initiated remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125003 1 Ffmpeg 1 Ffmpeg 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
A vulnerability was found in FFmpeg 2.0 and classified as problematic. This issue affects the function get_siz of the file libavcodec/jpeg2000dec.c. The manipulation leads to memory corruption. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125002 1 Ffmpeg 1 Ffmpeg 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
A vulnerability was found in FFmpeg 2.0. It has been classified as problematic. Affected is the function dnxhd_init_rc of the file libavcodec/dnxhdenc.c. The manipulation leads to memory corruption. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.
CVE-2014-125001 1 Cardosystems 2 Scala Rider Q3, Scala Rider Q3 Firmware 2026-06-17 8.3 HIGH 8.1 HIGH
A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling the service is recommended.
CVE-2014-10402 1 Perl 1 Dbi 2026-06-17 3.6 LOW 6.1 MEDIUM
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
CVE-2014-10401 1 Perl 1 Dbi 2026-06-17 3.6 LOW 6.1 MEDIUM
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
CVE-2014-10400 1 Keplerproject 1 Cgilua 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
CVE-2014-10399 1 Keplerproject 1 Cgilua 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
CVE-2014-10398 1 Bssys 1 Rbs Bs-client. Retail Client 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client (aka RBS BS-Client. Retail Client) 2.5, 2.4, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) DICTIONARY, (2) FILTERIDENT, (3) FROMSCHEME, (4) FromPoint, or (5) FName_0 parameter and a valid sid parameter value.
CVE-2014-10397 1 Para 1 Antioch 2026-06-17 5.0 MEDIUM 7.5 HIGH
The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php.
CVE-2014-10396 1 Organizedthemes 1 Epic 2026-06-17 5.0 MEDIUM 7.5 HIGH
The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.
CVE-2014-10395 1 Codepeople 1 Polls Cp 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
CVE-2014-10394 1 Saschart 1 Rich Counter 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The rich-counter plugin before 1.2.0 for WordPress has JavaScript injection via a User-Agent header.
CVE-2014-10393 1 Cformsii Project 1 Cformsii 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The cforms2 plugin before 10.5 for WordPress has XSS.
CVE-2014-10392 1 Cformsii Project 1 Cformsii 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
The cforms2 plugin before 10.2 for WordPress has XSS.