Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2014-04-14 CVE-2014-0612 Denial of Service vulnerability in Juniper Junos Branch SRX Series
Unspecified vulnerability in Juniper Junos before 11.4R10-S1, before 11.4R11, 12.1X44 before 12.1X44-D26, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, and 12.1X46 before 12.1X46-D10, when Dynamic IPsec VPN is configured, allows remote attackers to cause a denial of service (new Dynamic VPN connection failures and CPU and disk consumption) via unknown vectors.
network
low complexity
juniper
5.0
2014-04-14 CVE-2014-0159 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service (crash) via a crafted statsVersion argument.
network
low complexity
openafs debian CWE-119
5.0
2014-04-14 CVE-2014-0128 Improper Input Validation vulnerability in multiple products
Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.
network
low complexity
squid-cache opensuse CWE-20
5.0
2014-04-12 CVE-2014-2389 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Blackberry OS and Blackberry Z10
Stack-based buffer overflow in a certain decryption function in qconnDoor on BlackBerry Z10 devices with software 10.1.0.2312, when developer-mode has been previously enabled, allows remote attackers to execute arbitrary code via a crafted packet in a TCP session on a wireless network.
network
blackberry CWE-119
critical
9.3
2014-04-12 CVE-2014-2142 Denial of Service vulnerability in Cisco products
Cisco ONS 15454 controller cards with software 10.0 and earlier allow remote attackers to cause a denial of service (card reload) via a crafted HTTP URI, aka Bug ID CSCun06870.
network
low complexity
cisco
5.0
2014-04-12 CVE-2014-2140 Denial of Service vulnerability in Cisco ONS 15454 System Software and ONS 15454
Cisco ONS 15454 controller cards with software 9.6 and earlier allow remote attackers to cause a denial of service (card reset) via a TCP FIN attack that triggers file-descriptor exhaustion and a failure to open a CAL pipe, aka Bug ID CSCug97348.
network
low complexity
cisco
5.0
2014-04-12 CVE-2014-2139 Denial of Service vulnerability in Cisco ONS 15454 System Software and ONS 15454
Cisco ONS 15454 controller cards with software 9.6 and earlier allow remote attackers to cause a denial of service (flash write outage) via a TCP FIN attack that triggers file-descriptor exhaustion, aka Bug ID CSCug97315.
network
low complexity
cisco
5.0
2014-04-12 CVE-2014-0787 Buffer Errors vulnerability in Wellintech Kingscada 3.1/3.1.2
Stack-based buffer overflow in WellinTech KingSCADA before 3.1.2.13 allows remote attackers to execute arbitrary code via a crafted packet.
network
low complexity
wellintech CWE-119
critical
10.0
2014-04-12 CVE-2014-0773 Security Bypass vulnerability in Advantech Webaccess 5.0/6.0/7.0
The CreateProcess method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to execute (1) setup.exe, (2) bwvbprt.exe, and (3) bwvbprtl.exe programs from arbitrary pathnames via a crafted argument, as demonstrated by a UNC share pathname.
network
low complexity
advantech
7.5
2014-04-12 CVE-2014-0772 Information Exposure vulnerability in Advantech Webaccess 5.0/6.0/7.0
The OpenUrlToBufferTimeout method in the BWOCXRUN.BwocxrunCtrl.1 ActiveX control in bwocxrun.ocx in Advantech WebAccess before 7.2 allows remote attackers to read arbitrary files via a file: URL.
network
low complexity
advantech CWE-200
5.0