Search

Found 1,064 results in 328ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2014-3504 medium 4.0 FIX ubuntu ubuntudebian debian apacheserf_project 12y ago The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly handle a NUL byte in a domain name in t…
CVE-2014-5207 medium 7.2 EXPFIX debian debian linux-kernelubuntu ubuntu 12y ago fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows …
CVE-2014-5031 medium 5.0 FIX debian debianubuntu ubuntu apple 12y ago The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.
CVE-2014-4909 medium 6.8 FIX fedora fedoraubuntu ubuntugentoo gentoo transmissionbt 12y ago Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via …
CVE-2014-1419 medium 6.9 FIX debian debianubuntu ubuntu canonical 12y ago Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors.
CVE-2014-4699 medium 7.9 EXPFIX debian debian linux-kernelubuntu ubuntu 12y ago The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows …
CVE-2014-0247 critical 10.0 FIX debian debiansuse susefedora fedora libreoffice 12y ago LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
CVE-2014-4667 medium 5.0 FIX debian debiansuse suse linux-kernel 12y ago The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of servi…
CVE-2014-4656 medium 4.6 FIX debian debiansuse suse linux-kernel 12y ago Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX…
CVE-2014-4655 medium 4.9 FIX debian debiansuse suse linux-kernel 12y ago The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not properly maintain the user_ctl_count value, which allows local user…
CVE-2014-4654 medium 4.6 FIX suse suse linux-kerneldebian debian 12y ago The snd_ctl_elem_add function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not check authorization for SNDRV_CTL_IOCTL_ELEM_REPLACE commands, whic…
CVE-2014-4653 medium 4.6 FIX debian debiansuse suse linux-kernel 12y ago sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 does not ensure possession of a read/write lock, which allows local users to cause a denial of service (use-a…
CVE-2014-4508 medium 4.7 FIX slesdebian debianubuntu ubuntu 12y ago arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of se…
CVE-2014-4171 medium 4.7 FIX debian debianubuntu ubuntu linux-kernel 12y ago mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex …
CVE-2013-1068 medium 5.0 FIX debian debianubuntu ubuntu 12y ago The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.…
CVE-2014-3925 medium 5.0 FIX ubuntu ubuntu rheldebian debian redhat 12y ago sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing th…
CVE-2012-1166 critical 10.0 ubuntu ubuntu canonical 12y ago The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.
CVE-2014-3730 medium 4.3 FIX ubuntu ubuntususe susedebian debian djangoproject 12y ago The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to condu…
CVE-2014-1418 medium 6.4 FIX ubuntu ubuntudebian debian djangoproject 12y ago Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attacke…
CVE-2014-0209 medium 4.6 FIX ubuntu ubuntudebian debian x 12y ago Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a di…
CVE-2014-2405 critical 10.0 ubuntu ubuntudebian debian oracle 12y ago Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-0462.
CVE-2014-0462 critical 10.0 ubuntu ubuntudebian debian oracle 12y ago Unspecified vulnerability in OpenJDK 6 before 6b31 on Debian GNU/Linux and Ubuntu 12.04 LTS and 10.04 LTS has unknown impact and attack vectors, a different vulnerability than CVE-2014-2405.
CVE-2011-4407 medium 4.3 FIX ubuntu ubuntudebian debian canonical 12y ago ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys fo…
CVE-2014-3145 medium 4.9 FIX debian debianubuntu ubuntu linux-kernel 12y ago The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows …
CVE-2014-3144 medium 4.9 FIX debian debianubuntu ubuntu linux-kernel 12y ago The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain l…
CVE-2014-3122 medium 4.9 FIX debian debianubuntu ubuntu linux-kernel 12y ago The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system c…
CVE-2014-0190 medium 4.3 ubuntu ubuntususe susefedora fedora qt 12y ago The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
CVE-2013-4544 medium 4.9 FIX ubuntu ubuntudebian debian qemu 12y ago hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers o…
CVE-2014-3204 medium 4.4 ubuntu ubuntu ayatana_project 12y ago Unity before 7.2.1, as used in Ubuntu 14.04, does not properly handle keyboard shortcuts, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demo…
CVE-2014-3203 medium 4.4 ubuntu ubuntu ayatana_project 12y ago Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is active, which allows physically proximate attackers to bypass the lock screen and ex…
CVE-2013-7374 medium 4.6 ubuntu ubuntu 12y ago The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypa…
CVE-2014-0471 medium 5.0 FIX debian debianubuntu ubuntu debian 12y ago Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x before 1.16.13, and 1.17.x before 1.17.8 allows remote attackers to write arbitrary files via a crafted …
CVE-2014-1532 critical 9.8 9.8 ubuntu ubuntudebian debian rhel mozilla 12y ago Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonk…
CVE-2014-1530 medium 6.1 6.1 ubuntu ubuntudebian debian rhel mozilla 12y ago The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL wi…
CVE-2014-1528 critical 10.0 ubuntu ubuntususe susefedora fedora mozilla 12y ago The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of ser…
CVE-2014-1526 medium 6.8 ubuntu ubuntususe susefedora fedora mozilla 12y ago The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is vis…
CVE-2014-1525 critical 9.3 ubuntu ubuntususe susefedora fedora mozilla 12y ago The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remot…
CVE-2014-1524 critical 9.8 9.8 ubuntu ubuntudebian debian rhel mozilla 12y ago The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether obj…
CVE-2014-1523 medium 6.5 6.5 ubuntu ubuntudebian debian rhel mozilla 12y ago Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a…
CVE-2014-1522 critical 9.3 ubuntu ubuntususe susefedora fedora mozilla 12y ago The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or…
CVE-2014-1519 critical 9.3 ubuntu ubuntususe susefedora fedora mozilla 12y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and applicat…
CVE-2014-0187 critical 9.0 FIX debian debianubuntu ubuntususe suse openstack 12y ago The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a s…
CVE-2011-3152 medium 6.4 ubuntu ubuntu canonical 12y ago DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25…
CVE-2014-0474 critical 10.0 FIX ubuntu ubuntudebian debian djangoproject 12y ago The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not proper…
CVE-2014-0473 medium 5.0 FIX ubuntu ubuntudebian debian djangoproject 12y ago The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to…
CVE-2014-0472 medium 5.1 FIX ubuntu ubuntudebian debian djangoproject 12y ago The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Pyth…
CVE-2014-2421 critical 10.0 debian debianubuntu ubuntu oraclejuniperibm 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JavaFX 2.2.51; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availability via unkn…
CVE-2014-2413 medium 4.3 ubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect integrity via unknown vectors related to Libraries.
CVE-2014-2403 medium 5.0 debian debianubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality via vectors related to JAXP.
CVE-2014-2397 critical 9.3 debian debianubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspo…
CVE-2014-0461 critical 9.3 debian debianubuntu ubuntu oracleibm 12y ago Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to…
CVE-2014-0460 medium 5.8 debian debianubuntu ubuntu oraclejuniper 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via vecto…
CVE-2014-0459 medium 4.3 FIX debian debianubuntu ubuntu oracle 12y ago Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect availability via unknown vectors related to 2D.
CVE-2014-0457 critical 10.0 debian debianubuntu ubuntu oraclejuniperibm 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, SE 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and avai…
CVE-2014-0456 critical 10.0 debian debianubuntu ubuntu oraclejuniperibm 12y ago Unspecified vulnerability in Oracle Java SE 6u71, 7u51, and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to…
CVE-2014-0455 critical 9.3 ubuntu ubuntu oracleibm 12y ago Unspecified vulnerability in Oracle Java SE 7u51 and 8, and Java SE Embedded 7u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Librar…
CVE-2014-0453 medium 4.0 debian debianubuntu ubuntu oraclejuniperibm 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality and integrity via unkno…
CVE-2014-0429 critical 10.0 debian debianubuntu ubuntu oraclejuniperibm 12y ago Unspecified vulnerability in Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 allows remote attackers to affect confidentiality, integrity, and availab…
CVE-2011-3628 medium 6.9 FIX ubuntu ubuntudebian debian canonical 12y ago Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ub…
CVE-2013-5704 medium 5.0 FIX debian debian rhelmacos macos apacheredhatoracle 12y ago The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfe…
CVE-2014-2523 critical 10.0 FIX debian debianubuntu ubuntu linux-kernel 12y ago net/netfilter/nf_conntrack_proto_dccp.c in the Linux kernel through 3.13.6 uses a DCCP header pointer incorrectly, which allows remote attackers to cause a denial of service (system crash) or possibl…
CVE-2014-2497 medium 4.3 FIX debian debianubuntu ubuntususe suse php 12y ago The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a c…
CVE-2014-1514 critical 9.8 9.8 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a …
CVE-2014-1512 critical 10.0 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows r…
CVE-2014-1511 critical 9.8 10.0 EXP ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.
CVE-2014-1510 critical 9.8 10.0 EXP ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript cod…
CVE-2014-1508 critical 9.1 9.1 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive…
CVE-2014-1493 critical 9.8 9.8 ubuntu ubuntudebian debiansuse suse mozillasuse 12y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to c…
CVE-2014-2241 medium 6.8 FIX debian debianubuntu ubuntu freetype 12y ago The (1) cf2_initLocalRegionBuffer and (2) cf2_initGlobalRegionBuffer functions in cff/cf2ft.c in FreeType before 2.5.3 do not properly check if a subroutine exists, which allows remote attackers to c…
CVE-2014-0098 medium 5.0 FIX debian debianubuntu ubuntu apacheoracle 12y ago The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon cra…
CVE-2013-6438 medium 5.0 FIX debian debianubuntu ubuntu apacheoracle 12y ago The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote atta…
CVE-2014-2270 medium 4.3 FIX debian debianubuntu ubuntususe suse file_projectphp 12y ago softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE execu…
CVE-2013-6476 medium 4.4 FIX debian debianubuntu ubuntufedora fedora linuxfoundation 12y ago The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same…
CVE-2013-6475 medium 6.8 FIX debian debianubuntu ubuntufedora fedora linuxfoundation 12y ago Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a c…
CVE-2013-6474 medium 6.8 FIX debian debianubuntu ubuntufedora fedora linuxfoundation 12y ago Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
CVE-2013-6473 medium 6.8 FIX debian debianubuntu ubuntu linuxfoundation 12y ago Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.
CVE-2013-4496 medium 5.0 FIX ubuntu ubuntudebian debian samba 12y ago Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obta…
CVE-2014-0004 medium 6.9 FIX ubuntu ubuntudebian debian freedesktop 12y ago Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.
CVE-2014-1874 medium 4.9 FIX debian debiansuse suseubuntu ubuntu 12y ago The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_…
CVE-2014-1943 medium 5.0 FIX debian debianubuntu ubuntu fine_free_file_projectphp 13y ago Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.
CVE-2013-7327 medium 6.8 ubuntu ubuntu php 13y ago The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspeci…
CVE-2012-3406 medium 6.8 FIX debian debian rhelubuntu ubuntu gnuredhat 13y ago The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SP…
CVE-2012-3405 medium 5.0 FIX debian debian rhelubuntu ubuntu gnuredhat 13y ago The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to …
CVE-2012-3404 medium 5.0 FIX debian debian rhelubuntu ubuntu gnuredhat 13y ago The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to …
CVE-2013-6393 medium 6.8 FIX debian debiansuse suseubuntu ubuntu pyyamlredhat 13y ago Heap Based Buffer Overflow in libyaml
CVE-2013-2038 medium 4.3 FIX slesdebian debianubuntu ubuntu gpsd_project 13y ago The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpret…
CVE-2014-1491 medium 4.3 FIX debian debiansuse suseubuntu ubuntu mozillaoracle 13y ago Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does n…
CVE-2014-1490 critical 9.3 FIX suse susedebian debianubuntu ubuntu mozillaoracle 13y ago Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24…
CVE-2014-1489 medium 4.3 suse suseubuntu ubuntu mozilla 13y ago Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore…
CVE-2014-1488 critical 10.0 suse suseubuntu ubuntu mozilla 13y ago The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that ha…
CVE-2014-1486 critical 9.8 9.8 fedora fedorasuse suse rhel mozillasuse 13y ago Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers t…
CVE-2014-1483 medium 5.0 suse suseubuntu ubuntu mozillasuse 13y ago Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain t…
CVE-2014-1480 medium 4.3 suse suseubuntu ubuntu mozilla 13y ago The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjac…
CVE-2014-1478 critical 10.0 suse suseubuntu ubuntu mozilla 13y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and applicat…
CVE-2014-1477 critical 9.8 9.8 rhelubuntu ubuntudebian debian mozillasuse 13y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to c…
CVE-2011-4613 medium 5.6 EXPFIX ubuntu ubuntudebian debian x.org 13y ago The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restricti…
CVE-2011-3377 medium 4.3 FIX debian debiansuse suseubuntu ubuntu redhat 13y ago The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network conne…
CVE-2011-2725 medium 6.8 suse suseubuntu ubuntu kde 13y ago Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.
CVE-2013-0339 medium 6.8 FIX debian debianubuntu ubuntususe suse xmlsoft 13y ago libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote at…
CVE-2013-6425 medium 5.0 FIX debian debianubuntu ubuntususe suse pixman 13y ago Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) v…