CVE-2014-1754
published 2014-05-14CVE-2014-1754: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
11.07%
95.4th percentile
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office_web_apps_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server_client_components_sdk | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qpfr-mc5h-6r6v: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Se
ghsa_unreviewed·2022-05-14
CVE-2014-1754 [MEDIUM] CWE-79 GHSA-qpfr-mc5h-6r6v: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Se
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."
Red Hat
kernel: bcachefs: kvfree bch_fs::snapshots in bch2_fs_snapshots_exit
vendor_redhat·2024-05-17·CVSS 5.5
CVE-2024-35832 [MEDIUM] CWE-119 kernel: bcachefs: kvfree bch_fs::snapshots in bch2_fs_snapshots_exit
kernel: bcachefs: kvfree bch_fs::snapshots in bch2_fs_snapshots_exit
In the Linux kernel, the following vulnerability has been resolved:
bcachefs: kvfree bch_fs::snapshots in bch2_fs_snapshots_exit
bch_fs::snapshots is allocated by kvzalloc in __snapshot_t_mut.
It should be freed by kvfree not kfree.
Or umount will triger:
[ 406.829178 ] BUG: unable to handle page fault for address: ffffe7b487148008
[ 406.830676 ] #PF: supervisor read access in kernel mode
[ 406.831643 ] #PF: error_code(0x0000) - not-present page
[ 406.832487 ] PGD 0 P4D 0
[ 406.832898 ] Oops: 0000 [#1] PREEMPT SMP PTI
[ 406.833512 ] CPU: 2 PID: 1754 Comm: umount Kdump: loaded Tainted: G OE 6.7.0-rc7-custom+ #90
[ 406.834746 ] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014
[ 4
No detection rules found.
Talos
Microsoft Update Tuesday May 2014: relatively light month
blogs_talos·2014-05-13·CVSS 4.3
[MEDIUM] Microsoft Update Tuesday May 2014: relatively light month
## Microsoft Update Tuesday May 2014: relatively light month
It’s time for another Microsoft Update Tuesday , the first one which will not feature any XP updates (except of course for the out-of-band patch ( MS14-021 ) which was released to deal with the IE 0-day which is officially part of this release, but which we won't be discussing here, more on that can be found here and here ). It’s a pretty straightforward month this time around, with eight bulletins covering 13 CVEs.
The numbering is a little off this month, usually the critical bulletins came first, but it seems that Microsoft hasn't done that this time around. We’ll list the critical bulletins first, followed by the important ones.
There’s two critical bulletins and six important bulletins this month:
The first critical bull
Talos
Microsoft Update Tuesday May 2014: relatively light month
blogs_talos·2014-05-13·CVSS 4.3
[MEDIUM] Microsoft Update Tuesday May 2014: relatively light month
It’s time for another Microsoft Update Tuesday, the first one which will not feature any XP updates (except of course for the out-of-band patch (MS14-021) which was released to deal with the IE 0-day which is officially part of this release, but which we won't be discussing here, more on that can be found here and here). It’s a pretty straightforward month this time around, with eight bulletins covering 13 CVEs.
The numbering is a little off this month, usually the critical bulletins came first, but it seems that Microsoft hasn't done that this time around. We’ll list the critical bulletins first, followed by the important ones.
There’s two critical bulletins and six important bulletins this month:
The first critical bulletin is MS14-022 and covers three CVEs in Sharepoint. Two of them
http://www.securityfocus.com/bid/67288http://www.securitytracker.com/id/1030227https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-022http://www.securityfocus.com/bid/67288http://www.securitytracker.com/id/1030227https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-022
2014-05-14
Published