Search

Found 937 results in 161ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-0383 medium 5.4 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via un…
CVE-2015-0382 medium 4.3 ubuntu ubuntususe susedebian debian oraclemariadb 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a differ…
CVE-2015-0381 medium 4.3 ubuntu ubuntususe susedebian debian oraclemariadb 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a differ…
CVE-2015-0374 low 3.5 ubuntu ubuntususe susedebian debian oraclemariadb 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security…
CVE-2014-6568 low 3.5 ubuntu ubuntususe susedebian debian oraclemariadb 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
CVE-2015-0221 medium 5.0 FIX ubuntu ubuntudebian debian djangoproject 12y ago The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of servic…
CVE-2015-0220 medium 4.3 FIX ubuntu ubuntudebian debian djangoproject 12y ago The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct c…
CVE-2014-9496 low 2.1 FIX ubuntu ubuntususe susedebian debian libsndfile_project 12y ago The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.
CVE-2014-8738 medium 5.0 FIX debian debianfedora fedoraubuntu ubuntu gnu 12y ago The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a…
CVE-2014-8150 medium 4.3 FIX debian debianubuntu ubuntu haxx 12y ago CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks v…
CVE-2014-9585 low 2.1 FIX debian debianfedora fedorasuse suse 12y ago The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR …
CVE-2014-9584 low 2.1 FIX debian debiansuse suse rhel 12y ago The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows loca…
CVE-2014-9529 medium 6.9 FIX debian debianfedora fedorasuse suse 12y ago Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly hav…
CVE-2014-9221 medium 5.0 FIX debian debianfedora fedorasuse suse strongswan 12y ago strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) g…
CVE-2014-1425 low 2.1 ubuntu ubuntu linuxcontainers 12y ago cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
CVE-2014-8109 medium 4.3 FIX debian debianfedora fedoraubuntu ubuntu apacheoracle 12y ago mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different ar…
CVE-2014-8132 medium 5.0 FIX debian debianfedora fedorasuse suse libssh 12y ago Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.
CVE-2014-8136 low 2.1 FIX debian debiansuse suse rhel redhat 12y ago The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denia…
CVE-2014-8117 medium 5.0 FIX debian debianubuntu ubuntufreebsd freebsd file_project 12y ago softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
CVE-2014-8116 medium 5.0 FIX debian debianubuntu ubuntufreebsd freebsd file_project 12y ago The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid …
CVE-2014-5353 low 3.5 FIX debian debianfedora fedora rhel mit 12y ago The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated us…
CVE-2014-9323 medium 5.0 debian debianubuntu ubuntu firebirdsql 12y ago The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via a…
CVE-2014-6053 medium 5.0 FIX debian debianubuntu ubuntu libvncserver 12y ago The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows r…
CVE-2014-3583 medium 5.0 FIX debian debianubuntu ubuntumacos macos apache 12y ago The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon c…
CVE-2014-8134 low 3.3 3.3 FIX debian debian linux-kernelsuse suse 12y ago The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to …
CVE-2014-8602 medium 4.3 FIX debian debianubuntu ubuntu nlnetlabs 12y ago iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite numbe…
CVE-2014-8737 low 3.6 FIX debian debianubuntu ubuntufedora fedora gnu 12y ago Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcop…
CVE-2014-8484 medium 5.0 FIX slesdebian debianubuntu ubuntu gnu 12y ago The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
CVE-2012-6656 medium 5.0 FIX debian debianubuntu ubuntu gnu 12y ago iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the ico…
CVE-2014-8104 medium 6.8 FIX suse susedebian debianubuntu ubuntu openvpn 12y ago OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
CVE-2014-7142 medium 6.4 FIX ubuntu ubuntudebian debian squid-cache 12y ago The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.
CVE-2014-7817 medium 4.6 FIX debian debiansuse suseubuntu ubuntu gnu 12y ago The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containin…
CVE-2014-8768 medium 6.0 EXPFIX suse suseubuntu ubuntudebian debian redhat 12y ago Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a…
CVE-2014-7824 low 2.1 FIX debian debianubuntu ubuntu freedesktop 12y ago D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the…
CVE-2014-5388 medium 4.6 FIX ubuntu ubuntudebian debian qemu 12y ago Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact relate…
CVE-2014-4975 medium 5.0 debian debianubuntu ubuntu rhel ruby-lang 12y ago Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial …
CVE-2014-3707 medium 4.3 FIX debian debianmacos macossuse suse oraclehaxx 12y ago The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out…
CVE-2014-7815 medium 5.0 FIX debian debiansuse suseubuntu ubuntu qemuredhat 12y ago The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
CVE-2014-8564 medium 5.0 FIX debian debiansuse suseubuntu ubuntu gnu 12y ago The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds…
CVE-2014-8559 medium 5.5 5.5 FIX debian debian linux-kernelsuse suse 12y ago The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and syst…
CVE-2014-3690 medium 5.5 5.5 FIX debian debian linux-kernelsuse suse 12y ago arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allow…
CVE-2014-3647 medium 5.5 5.5 FIX slesdebian debian linux-kernel 12y ago arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a c…
CVE-2014-3646 medium 5.5 5.5 FIX debian debian linux-kernelsuse suse 12y ago arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest O…
CVE-2014-3611 medium 4.7 4.7 FIX debian debian linux-kernelubuntu ubuntu 12y ago Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS cras…
CVE-2014-3610 medium 5.5 5.5 FIX debian debian linux-kernelsuse suse 12y ago The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows g…
CVE-2014-3640 low 2.1 FIX debian debianubuntu ubuntu rhel qemu 12y ago The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and a…
CVE-2014-8483 medium 5.0 FIX slesdebian debiansuse suse quassel-irc 12y ago The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
CVE-2014-3710 medium 5.0 FIX debian debianubuntu ubuntu php 12y ago The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to caus…
CVE-2014-3660 medium 5.0 FIX slesdebian debianmacos macos xmlsoft 12y ago parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU…
CVE-2014-8080 medium 5.0 suse suseubuntu ubuntu rhel ruby-lang 12y ago The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document,…
CVE-2014-3615 low 2.1 FIX slesdebian debiansuse suse qemuredhat 12y ago The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
CVE-2014-3694 medium 6.4 FIX debian debiansuse suseubuntu ubuntu pidgin 12y ago The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of …
CVE-2014-0476 low 4.7 EXPFIX debian debianubuntu ubuntu chkrootkit 12y ago The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerabilit…
CVE-2014-3564 medium 6.8 FIX debian debianubuntu ubuntu gnu 12y ago Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) a…
CVE-2014-3686 medium 6.8 FIX debian debianubuntu ubuntu w1.fi 12y ago wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via …
CVE-2014-1829 medium 5.0 FIX debian debianubuntu ubuntu python 12y ago Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
CVE-2014-7975 medium 5.5 5.5 FIX debian debian linux-kernelubuntu ubuntu 12y ago The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which all…
CVE-2014-7970 medium 5.5 5.5 FIX debian debiansuse suse linux-kernel 12y ago The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of…
CVE-2014-3581 medium 5.0 FIX debian debianubuntu ubuntu rhel apacheoracle 12y ago The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer d…
CVE-2014-7230 low 2.1 FIX debian debianubuntu ubuntu openstackredhat 12y ago The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a Pro…
CVE-2014-7204 medium 5.0 FIX debian debianubuntu ubuntu debian 12y ago jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
CVE-2014-3565 medium 5.0 FIX debian debianmacos macosubuntu ubuntu net-snmp 12y ago snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conv…
CVE-2014-6054 medium 4.3 FIX debian debianubuntu ubuntu libvncserver 12y ago The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) v…
CVE-2014-3633 medium 5.8 FIX debian debianubuntu ubuntu libvirt 12y ago The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of serv…
CVE-2014-6414 medium 4.0 FIX debian debianubuntu ubuntu openstack 12y ago OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
CVE-2014-3621 medium 4.0 FIX debian debianubuntu ubuntu rhel openstackredhat 12y ago The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpo…
CVE-2014-3186 medium 6.9 FIX debian debian linux-kernelubuntu ubuntu 12y ago Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows …
CVE-2014-5461 medium 5.0 FIX arch archsuse suseubuntu ubuntu lua 12y ago Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a fun…
CVE-2014-3601 medium 4.3 FIX suse suseubuntu ubuntu linux-kernel suse 12y ago The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) …
CVE-2014-5252 medium 4.9 FIX debian debianubuntu ubuntu openstack 12y ago The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the tok…
CVE-2014-5251 medium 4.9 FIX debian debianubuntu ubuntu openstack 12y ago The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for to…
CVE-2014-5033 medium 6.9 ubuntu ubuntu debiankde 12y ago KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a Pol…
CVE-2014-4615 medium 5.0 FIX debian debianubuntu ubuntu redhatopenstack 12y ago The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Osl…
CVE-2014-3528 medium 4.0 FIX suse suseubuntu ubuntu rhel apacheapple 12y ago Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers …
CVE-2014-3522 medium 4.0 FIX suse suseubuntu ubuntudebian debian apacheapple 12y ago The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certif…
CVE-2014-3504 medium 4.0 FIX ubuntu ubuntudebian debian apacheserf_project 12y ago The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in t…
CVE-2014-5207 medium 7.2 EXPFIX debian debian linux-kernelubuntu ubuntu 12y ago fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows …
CVE-2014-5031 medium 5.0 FIX debian debianubuntu ubuntu apple 12y ago The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.
CVE-2014-5030 low 1.9 FIX debian debianubuntu ubuntu apple 12y ago CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.
CVE-2014-5029 low 1.5 FIX debian debianubuntu ubuntu apple 12y ago The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerabilit…
CVE-2014-4909 medium 6.8 FIX fedora fedoraubuntu ubuntugentoo gentoo transmissionbt 12y ago Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via …
CVE-2014-1419 medium 6.9 FIX debian debianubuntu ubuntu canonical 12y ago Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors.
CVE-2014-3537 low 1.2 FIX debian debianfedora fedoraubuntu ubuntu apple 12y ago The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
CVE-2014-4167 low 3.5 FIX debian debianubuntu ubuntu openstack 12y ago The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by at…
CVE-2014-4699 medium 7.9 EXPFIX debian debian linux-kernelubuntu ubuntu 12y ago The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows …
CVE-2014-4667 medium 5.0 FIX debian debiansuse suse linux-kernel 12y ago The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of servi…
CVE-2014-4656 medium 4.6 FIX debian debiansuse suse linux-kernel 12y ago Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX…
CVE-2014-4655 medium 4.9 FIX debian debiansuse suse linux-kernel 12y ago The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local user…
CVE-2014-4654 medium 4.6 FIX suse suse linux-kerneldebian debian 12y ago The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, whic…
CVE-2014-4653 medium 4.6 FIX debian debiansuse suse linux-kernel 12y ago sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-a…
CVE-2014-4652 low 1.9 FIX debian debiansuse suse linux-kernel 12y ago Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users t…
CVE-2014-4508 medium 4.7 FIX slesdebian debianubuntu ubuntu 12y ago arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of se…
CVE-2014-4171 medium 4.7 FIX debian debianubuntu ubuntu linux-kernel 12y ago mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex …
CVE-2014-4027 low 2.3 FIX debian debianubuntu ubuntususe suse f5 12y ago The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensiti…
CVE-2014-1739 low 3.1 EXPFIX debian debianubuntu ubuntususe suse 12y ago The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive in…
CVE-2013-1068 medium 5.0 FIX debian debianubuntu ubuntu 12y ago The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.…
CVE-2014-3925 medium 5.0 FIX ubuntu ubuntu rheldebian debian redhat 12y ago sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing th…
CVE-2012-6648 low 2.1 ubuntu ubuntu gdm-guest-session_project 12y ago gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04, allows local users to delete arbitrary files via a space in the name of a file…
CVE-2012-0943 low 3.1 EXPFIX ubuntu ubuntudebian debian robert_ancell 12y ago debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name …
CVE-2014-3730 medium 4.3 FIX ubuntu ubuntususe susedebian debian djangoproject 12y ago The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to condu…