Search

Found 1,064 results in 402ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2015-2304 medium 6.4 FIX debian debianubuntu ubuntususe suse libarchive 11y ago Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive.
CVE-2015-1229 medium 5.0 rhelubuntu ubuntu google 11y ago net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allo…
CVE-2015-1220 medium 6.8 ubuntu ubuntu google 11y ago Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attacker…
CVE-2015-0228 medium 5.0 FIX debian debianubuntu ubuntususe suse apache 11y ago The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a…
CVE-2015-0239 medium 4.4 FIX slesdebian debian rhel 11y ago The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a…
CVE-2014-8160 medium 5.0 FIX slesdebian debian rhel 11y ago net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite pr…
CVE-2015-0834 medium 4.3 ubuntu ubuntususe suse mozilla 11y ago The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to …
CVE-2015-0832 medium 5.0 ubuntu ubuntususe suse mozilla 11y ago Mozilla Firefox before 36.0 does not properly recognize the equivalence of domain names with and without a trailing . (dot) character, which allows man-in-the-middle attackers to bypass the HPKP and …
CVE-2015-0831 medium 6.8 rhelubuntu ubuntu mozilla 11y ago Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remo…
CVE-2015-0830 medium 5.0 ubuntu ubuntususe suse mozilla 11y ago The WebGL implementation in Mozilla Firefox before 36.0 does not properly allocate memory for copying an unspecified string to a shader's compilation log, which allows remote attackers to cause a den…
CVE-2015-0829 medium 6.8 ubuntu ubuntususe suse mozilla 11y ago Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
CVE-2015-0826 medium 6.8 ubuntu ubuntususe suse mozilla 11y ago The nsTransformedTextRun::SetCapitalization function in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read of heap memory) …
CVE-2015-0825 medium 4.3 ubuntu ubuntususe suse mozilla 11y ago Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malf…
CVE-2015-0824 medium 5.0 ubuntu ubuntususe suse mozilla 11y ago The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and appl…
CVE-2015-0821 medium 6.8 ubuntu ubuntususe suse mozilla 11y ago Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unsp…
CVE-2015-0819 medium 4.3 ubuntu ubuntususe suse mozilla 11y ago The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking a…
CVE-2015-1572 medium 4.6 FIX slesdebian debianubuntu ubuntu e2fsprogs_project 11y ago Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as d…
CVE-2013-7423 medium 5.0 FIX slesdebian debianubuntu ubuntu gnu 11y ago The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended l…
CVE-2015-0240 critical 10.0 EXPFIX rhelubuntu ubuntususe suse samba 11y ago The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized st…
CVE-2014-9679 medium 6.8 FIX slesdebian debianubuntu ubuntu apple 11y ago Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via a malformed compressed raster file, which trigger…
CVE-2015-0247 medium 4.6 FIX slesdebian debianubuntu ubuntu e2fsprogs_project 12y ago Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
CVE-2014-9675 medium 5.0 FIX debian debianubuntu ubuntu rhel freetype 12y ago bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the AS…
CVE-2014-9673 medium 6.8 FIX debian debian rhelubuntu ubuntu freetype 12y ago Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly…
CVE-2014-9672 medium 5.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information from pr…
CVE-2014-9671 medium 4.3 FIX debian debian rhelubuntu ubuntu freetype 12y ago Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via…
CVE-2014-9670 medium 4.3 FIX debian debian rhelubuntu ubuntu freetype 12y ago Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dere…
CVE-2014-9669 medium 6.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other i…
CVE-2014-9667 medium 6.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of…
CVE-2014-9666 medium 6.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a den…
CVE-2014-9664 medium 6.8 FIX debian debianubuntu ubuntususe suse freetype 12y ago FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecifi…
CVE-2014-9636 medium 5.0 FIX ubuntu ubuntudebian debianfedora fedora unzip_project 12y ago unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip arc…
CVE-2015-1210 medium 5.0 ubuntu ubuntususe susemacos macos google 12y ago The V8ThrowException::createDOMException function in bindings/core/v8/V8ThrowException.cpp in the V8 bindings in Blink, as used in Google Chrome before 40.0.2214.111 on Windows, OS X, and Linux and b…
CVE-2014-7943 medium 5.0 ubuntu ubuntususe suse chromiumgoogle 12y ago Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.
CVE-2015-0432 medium 4.0 ubuntu ubuntususe susedebian debian oraclemariadb 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
CVE-2015-0410 medium 5.0 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows rem…
CVE-2015-0408 critical 10.0 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI.
CVE-2015-0407 medium 5.0 FIX ubuntu ubuntudebian debianfedora fedora oracle 12y ago Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
CVE-2015-0400 medium 5.0 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
CVE-2015-0395 critical 9.3 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVE-2015-0383 medium 5.4 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via un…
CVE-2015-0382 medium 4.3 ubuntu ubuntususe susedebian debian oraclemariadb 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a differ…
CVE-2015-0381 medium 4.3 ubuntu ubuntususe susedebian debian oraclemariadb 12y ago Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a differ…
CVE-2014-6601 critical 10.0 FIX ubuntu ubuntususe susedebian debian oracle 12y ago Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVE-2015-0221 medium 5.0 FIX ubuntu ubuntudebian debian djangoproject 12y ago The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of servic…
CVE-2015-0220 medium 4.3 FIX ubuntu ubuntudebian debian djangoproject 12y ago The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct c…
CVE-2014-8738 medium 5.0 FIX debian debianfedora fedoraubuntu ubuntu gnu 12y ago The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a…
CVE-2014-8150 medium 4.3 FIX debian debianubuntu ubuntu haxx 12y ago CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks v…
CVE-2014-9529 medium 6.9 FIX debian debianfedora fedorasuse suse 12y ago Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly hav…
CVE-2014-9221 medium 5.0 FIX debian debianfedora fedorasuse suse strongswan 12y ago strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) g…
CVE-2014-8109 medium 4.3 FIX debian debianfedora fedoraubuntu ubuntu apacheoracle 12y ago mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different ar…
CVE-2014-8132 medium 5.0 FIX debian debianfedora fedorasuse suse libssh 12y ago Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.
CVE-2014-8117 medium 5.0 FIX debian debianubuntu ubuntufreebsd freebsd file_project 12y ago softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.
CVE-2014-8116 medium 5.0 FIX debian debianubuntu ubuntufreebsd freebsd file_project 12y ago The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid …
CVE-2014-9323 medium 5.0 debian debianubuntu ubuntu firebirdsql 12y ago The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via a…
CVE-2014-6053 medium 5.0 FIX debian debianubuntu ubuntu libvncserver 12y ago The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows r…
CVE-2014-3583 medium 5.0 FIX debian debianubuntu ubuntumacos macos apache 12y ago The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon c…
CVE-2014-8602 medium 4.3 FIX debian debianubuntu ubuntu nlnetlabs 12y ago iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite numbe…
CVE-2014-8484 medium 5.0 FIX slesdebian debianubuntu ubuntu gnu 12y ago The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
CVE-2012-6656 medium 5.0 FIX debian debianubuntu ubuntu gnu 12y ago iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the ico…
CVE-2014-8104 medium 6.8 FIX suse susedebian debianubuntu ubuntu openvpn 12y ago OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
CVE-2014-7142 medium 6.4 FIX ubuntu ubuntudebian debian squid-cache 12y ago The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.
CVE-2014-7817 medium 4.6 FIX debian debiansuse suseubuntu ubuntu gnu 12y ago The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containin…
CVE-2014-8768 medium 6.0 EXPFIX suse suseubuntu ubuntudebian debian redhat 12y ago Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a…
CVE-2014-5388 medium 4.6 FIX ubuntu ubuntudebian debian qemu 12y ago Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact relate…
CVE-2014-4975 medium 5.0 debian debianubuntu ubuntu rhel ruby-lang 12y ago Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial …
CVE-2014-3707 medium 4.3 FIX debian debianmacos macossuse suse oraclehaxx 12y ago The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out…
CVE-2014-7815 medium 5.0 FIX debian debiansuse suseubuntu ubuntu qemuredhat 12y ago The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
CVE-2014-8564 medium 5.0 FIX debian debiansuse suseubuntu ubuntu gnu 12y ago The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds…
CVE-2014-8559 medium 5.5 5.5 FIX debian debian linux-kernelsuse suse 12y ago The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and syst…
CVE-2014-3690 medium 5.5 5.5 FIX debian debian linux-kernelsuse suse 12y ago arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allow…
CVE-2014-3647 medium 5.5 5.5 FIX slesdebian debian linux-kernel 12y ago arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a c…
CVE-2014-3646 medium 5.5 5.5 FIX debian debian linux-kernelsuse suse 12y ago arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest O…
CVE-2014-3611 medium 4.7 4.7 FIX debian debian linux-kernelubuntu ubuntu 12y ago Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS cras…
CVE-2014-3610 medium 5.5 5.5 FIX debian debian linux-kernelsuse suse 12y ago The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows g…
CVE-2014-8483 medium 5.0 FIX slesdebian debiansuse suse quassel-irc 12y ago The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.
CVE-2014-3710 medium 5.0 FIX debian debianubuntu ubuntu php 12y ago The donote function in readelf.c in file through 5.20, as used in the Fileinfo component in PHP 5.4.34, does not ensure that sufficient note headers are present, which allows remote attackers to caus…
CVE-2014-3660 medium 5.0 FIX slesdebian debianmacos macos xmlsoft 12y ago parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU…
CVE-2014-8080 medium 5.0 suse suseubuntu ubuntu rhel ruby-lang 12y ago The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document,…
CVE-2014-3694 medium 6.4 FIX debian debiansuse suseubuntu ubuntu pidgin 12y ago The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of …
CVE-2014-3564 medium 6.8 FIX debian debianubuntu ubuntu gnu 12y ago Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) a…
CVE-2014-3686 medium 6.8 FIX debian debianubuntu ubuntu w1.fi 12y ago wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via …
CVE-2014-1829 medium 5.0 FIX debian debianubuntu ubuntu python 12y ago Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
CVE-2014-7975 medium 5.5 5.5 FIX debian debian linux-kernelubuntu ubuntu 12y ago The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which all…
CVE-2014-7970 medium 5.5 5.5 FIX debian debiansuse suse linux-kernel 12y ago The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of…
CVE-2014-3581 medium 5.0 FIX debian debianubuntu ubuntu rhel apacheoracle 12y ago The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer d…
CVE-2014-7204 medium 5.0 FIX debian debianubuntu ubuntu debian 12y ago jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
CVE-2014-3565 medium 5.0 FIX debian debianmacos macosubuntu ubuntu net-snmp 12y ago snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conv…
CVE-2014-6054 medium 4.3 FIX debian debianubuntu ubuntu libvncserver 12y ago The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) v…
CVE-2014-3633 medium 5.8 FIX debian debianubuntu ubuntu libvirt 12y ago The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of serv…
CVE-2014-6414 medium 4.0 FIX debian debianubuntu ubuntu openstack 12y ago OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
CVE-2014-3621 medium 4.0 FIX debian debianubuntu ubuntu rhel openstackredhat 12y ago The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpo…
CVE-2014-3186 medium 6.9 FIX debian debian linux-kernelubuntu ubuntu 12y ago Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows …
CVE-2014-5461 medium 5.0 FIX arch archsuse suseubuntu ubuntu lua 12y ago Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a fun…
CVE-2014-3601 medium 4.3 FIX suse suseubuntu ubuntu linux-kernel suse 12y ago The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) …
CVE-2014-5252 medium 4.9 FIX debian debianubuntu ubuntu openstack 12y ago The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the tok…
CVE-2014-5251 medium 4.9 FIX debian debianubuntu ubuntu openstack 12y ago The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for to…
CVE-2014-5033 medium 6.9 ubuntu ubuntu debiankde 12y ago KDE kdelibs before 4.14 and kauth before 5.1 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a Pol…
CVE-2014-4615 medium 5.0 FIX debian debianubuntu ubuntu redhatopenstack 12y ago The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Osl…
CVE-2014-3528 medium 4.0 FIX suse suseubuntu ubuntu rhel apacheapple 12y ago Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers …
CVE-2014-3522 medium 4.0 FIX suse suseubuntu ubuntudebian debian apacheapple 12y ago The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certif…