VulDB Updates Updates
- CVE-2025-24859 | Apache Roller up to 6.1.4 session expirationby vuldb.com on April 12, 2025 at 3:14 pm
A vulnerability was found in Apache Roller up to 6.1.4. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to session expiration. This vulnerability is known as CVE-2025-24859. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2008-0785 | Cacti up to 0.8.7a Login graph_view.php login_username sql injection (EDB-31161 / Nessus ID 31048)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability was found in Cacti and classified as critical. This issue affects some unknown processing of the file graph_view.php of the component Login. The manipulation of the argument login_username leads to sql injection. The identification of this vulnerability is CVE-2008-0785. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1264 | Apple Mac OS X 10.9/10.9.1 Finder ACL access control (HT6150 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability, which was classified as problematic, was found in Apple Mac OS X 10.9/10.9.1. This affects an unknown part of the component Finder. The manipulation leads to improper access controls (ACL). This vulnerability is uniquely identified as CVE-2014-1264. Attacking locally is a requirement. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-2102 | Cisco Unified Contact Center Express 10.0(1) CCMConfig Page access control (XFDB-91433 / BID-65797)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability classified as problematic was found in Cisco Unified Contact Center Express 10.0(1). This vulnerability affects unknown code of the component CCMConfig Page. The manipulation leads to improper access controls. This vulnerability was named CVE-2014-2102. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1263 | Apple Mac OS X 10.9/10.9.1 cURL IP address cryptographic issues (HT6150 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability, which was classified as problematic, has been found in Apple Mac OS X 10.9/10.9.1. Affected by this issue is some unknown functionality of the component cURL. The manipulation leads to cryptographic issues (IP address). This vulnerability is handled as CVE-2014-1263. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1268 | Apple Safari up to 7.0.1 WebKit memory corruption (HT6145 / Nessus ID 72689)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability was found in Apple Safari up to 7.0.1 and classified as critical. Affected by this issue is some unknown functionality of the component WebKit. The manipulation leads to memory corruption. This vulnerability is handled as CVE-2014-1268. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1265 | Apple Mac OS X 10.7.5/10.8.5/10.9/10.9.1 System Clock access control (HT6150 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability has been found in Apple Mac OS X 10.7.5/10.8.5/10.9/10.9.1 and classified as problematic. This vulnerability affects unknown code of the component System Clock. The manipulation leads to improper access controls. This vulnerability was named CVE-2014-1265. It is possible to launch the attack on the local host. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1270 | Apple Safari up to 7.0.1 WebKit memory corruption (HT6145 / Nessus ID 72962)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability was found in Apple Safari up to 7.0.1. It has been declared as critical. This vulnerability affects unknown code of the component WebKit. The manipulation leads to memory corruption. This vulnerability was named CVE-2014-1270. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1269 | Apple Safari up to 7.0.1 WebKit memory corruption (HT6145 / Nessus ID 72962)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability was found in Apple Safari up to 7.0.1. It has been classified as critical. This affects an unknown part of the component WebKit. The manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-2014-1269. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1967 | 7andi-fs.co Denny’s prior 2.0.0 Certificates cryptographic issuesby vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability was found in 7andi-fs.co Denny’s. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Certificates. The manipulation leads to cryptographic issues. This vulnerability is known as CVE-2014-1967. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1968 | Riken XooNIps up to 3.47 cross site scripting (BID-65807)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability was found in Riken XooNIps up to 3.47. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. This vulnerability is handled as CVE-2014-1968. The attack may be launched remotely. There is no exploit available.
- CVE-2014-2075 | TIBCO Enterprise Administrator SDK 1.0.0 improper authentication (XFDB-91646 / SBV-44255)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability classified as very critical has been found in TIBCO Enterprise Administrator SDK 1.0.0. This affects an unknown part. The manipulation leads to improper authentication. This vulnerability is uniquely identified as CVE-2014-2075. It is possible to initiate the attack remotely. There is no exploit available.
- CVE-2014-0046 | Ember.js 1.2.0/1.2.1/1.3.0/1.3.1/1.4.0 cross site scripting (XFDB-91242 / BID-65579)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability classified as problematic was found in Ember.js 1.2.0/1.2.1/1.3.0/1.3.1/1.4.0. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability was named CVE-2014-0046. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1223 | Telligent Evolution 6.1.19/7.1.12/7.5.0/7.5.0.32466/7.6.7 msg cross site scripting (BID-65739 / SA56779)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability, which was classified as problematic, has been found in Telligent Evolution 6.1.19/7.1.12/7.5.0/7.5.0.32466/7.6.7. This issue affects some unknown processing. The manipulation of the argument msg leads to cross site scripting. The identification of this vulnerability is CVE-2014-1223. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1597 | i-doit up to 1.2.4 objID sql injection (EDB-39096 / XFDB-91269)by vuldb.com on April 12, 2025 at 3:05 pm
A vulnerability, which was classified as critical, was found in i-doit up to 1.2.4. Affected is an unknown function. The manipulation of the argument objID leads to sql injection. This vulnerability is traded as CVE-2014-1597. It is possible to launch the attack remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2024-30180 | Easy Social Feed Plugin up to 6.5.3 on WordPress cross site scriptingby vuldb.com on April 12, 2025 at 2:51 pm
A vulnerability classified as problematic was found in Easy Social Feed Plugin up to 6.5.3 on WordPress. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2024-30180. The attack can be launched remotely. There is no exploit available.
- CVE-2024-29805 | ShopUp Shipping with Venipak for WooCommerce Plugin up to 1.19.5 on WordPress cross site scriptingby vuldb.com on April 12, 2025 at 2:51 pm
A vulnerability was found in ShopUp Shipping with Venipak for WooCommerce Plugin up to 1.19.5 on WordPress. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-29805. The attack may be initiated remotely. There is no exploit available.
- CVE-2024-29792 | Unlimited Elements for Elementor Plugin up to 1.5.93 on WordPress cross site scriptingby vuldb.com on April 12, 2025 at 2:51 pm
A vulnerability classified as problematic has been found in Unlimited Elements for Elementor Plugin up to 1.5.93 on WordPress. Affected is an unknown function. The manipulation leads to cross site scripting. This vulnerability is traded as CVE-2024-29792. It is possible to launch the attack remotely. There is no exploit available.
- CVE-2024-30179 | BoldThemes Bold Page Builder Plugin up to 4.7.6 on WordPress cross site scriptingby vuldb.com on April 12, 2025 at 2:51 pm
A vulnerability, which was classified as problematic, has been found in BoldThemes Bold Page Builder Plugin up to 4.7.6 on WordPress. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. This vulnerability is handled as CVE-2024-30179. The attack may be launched remotely. There is no exploit available.
- CVE-2024-30181 | Plainware Locatoraid Store Locator Plugin up to 3.9.30 on WordPress cross site scriptingby vuldb.com on April 12, 2025 at 2:51 pm
A vulnerability, which was classified as problematic, was found in Plainware Locatoraid Store Locator Plugin up to 3.9.30 on WordPress. This affects an unknown part. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-30181. It is possible to initiate the attack remotely. There is no exploit available.
- CVE-2024-30186 | BdThemes Prime Slider Plugin up to 3.13.1 on WordPress cross site scriptingby vuldb.com on April 12, 2025 at 2:51 pm
A vulnerability has been found in BdThemes Prime Slider Plugin up to 3.13.1 on WordPress and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerability was named CVE-2024-30186. The attack can be initiated remotely. There is no exploit available.
- CVE-2014-1258 | Apple Mac OS X 10.8.5/10.9/10.9.1 CoreAnimation Image memory corruption (HT6150 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 2:42 pm
A vulnerability was found in Apple Mac OS X 10.8.5/10.9/10.9.1. It has been rated as critical. This issue affects some unknown processing of the component CoreAnimation. The manipulation as part of Image leads to memory corruption. The identification of this vulnerability is CVE-2014-1258. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1259 | Apple Mac OS X 10.7.5/10.8.5/10.9/10.9.1 File Bookmark File Name memory corruption (HT6150 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 2:42 pm
A vulnerability classified as critical has been found in Apple Mac OS X 10.7.5/10.8.5/10.9/10.9.1. Affected is an unknown function of the component File Bookmark Handler. The manipulation as part of File Name leads to memory corruption. This vulnerability is traded as CVE-2014-1259. It is possible to launch the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1260 | Apple Mac OS X 10.8.5 QuickLook Microsoft Office Document memory corruption (HT6150 / Nessus ID 72688)by vuldb.com on April 12, 2025 at 2:42 pm
A vulnerability classified as critical was found in Apple Mac OS X 10.8.5. Affected by this vulnerability is an unknown functionality of the component QuickLook. The manipulation as part of Microsoft Office Document leads to memory corruption. This vulnerability is known as CVE-2014-1260. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1248 | Apple QuickTime up to 7.7.4 ldat memory corruption (HT6151 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 2:42 pm
A vulnerability was found in Apple QuickTime up to 7.7.4. It has been rated as critical. Affected by this issue is some unknown functionality of the component ldat Handler. The manipulation leads to memory corruption. This vulnerability is handled as CVE-2014-1248. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1249 | Apple QuickTime up to 7.7.4 PSD Image memory corruption (HT6151 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 2:42 pm
A vulnerability classified as critical has been found in Apple QuickTime up to 7.7.4. This affects an unknown part of the component PSD Image Handler. The manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-2014-1249. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1250 | Apple QuickTime up to 7.7.4 ttfo Element Movie File memory corruption (HT6151 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 2:42 pm
A vulnerability classified as critical was found in Apple QuickTime up to 7.7.4. This vulnerability affects unknown code of the component ttfo Element Handler. The manipulation as part of Movie File leads to memory corruption. This vulnerability was named CVE-2014-1250. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1251 | Apple QuickTime up to 7.7.4 clef Movie File memory corruption (HT6151 / Nessus ID 72706)by vuldb.com on April 12, 2025 at 2:42 pm
A vulnerability has been found in Apple QuickTime up to 7.7.4 and classified as critical. Affected by this vulnerability is an unknown functionality of the component clef Handler. The manipulation as part of Movie File leads to memory corruption. This vulnerability is known as CVE-2014-1251. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1254 | Apple Mac OS X 10.8.5/10.9/10.9.1 Type 1 Fonts Movie File memory corruption (HT6150 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 2:42 pm
A vulnerability was found in Apple Mac OS X 10.8.5/10.9/10.9.1. It has been declared as critical. This vulnerability affects unknown code of the component Type 1 Fonts. The manipulation as part of Movie File leads to memory corruption. This vulnerability was named CVE-2014-1254. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2014-1256 | Apple Mac OS X up to 10.7.4 App Sandbox memory corruption (HT6150 / Nessus ID 72687)by vuldb.com on April 12, 2025 at 2:42 pm
A vulnerability, which was classified as critical, was found in Apple Mac OS X up to 10.7.4. This affects an unknown part of the component App Sandbox. The manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-2014-1256. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.