- EPSS 7.11%
- Published 18.12.2014 15:59:01
- Last modified 12.04.2025 10:46:40
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that triggers a lookup for a...
- EPSS 18.54%
- Published 18.12.2014 15:59:00
- Last modified 12.04.2025 10:46:40
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does n...
CVE-2014-9273
- EPSS 0.18%
- Published 08.12.2014 16:59:11
- Last modified 12.04.2025 10:46:40
lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write.
CVE-2012-6662
- EPSS 6.28%
- Published 24.11.2014 16:59:01
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not prope...
- EPSS 3.45%
- Published 15.11.2014 20:59:01
- Last modified 12.04.2025 10:46:40
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that tr...
- EPSS 0.81%
- Published 13.11.2014 21:32:13
- Last modified 12.04.2025 10:46:40
The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptograp...
CVE-2014-3640
- EPSS 0.05%
- Published 07.11.2014 19:55:02
- Last modified 12.04.2025 10:46:40
The sosendto function in slirp/udp.c in QEMU before 2.1.2 allows local users to cause a denial of service (NULL pointer dereference) by sending a udp packet with a value of 0 in the source port and address, which triggers access of an uninitialized s...
CVE-2014-7145
- EPSS 1.21%
- Published 28.09.2014 10:55:10
- Last modified 12.04.2025 10:46:40
The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ sh...
- EPSS 4.78%
- Published 19.08.2014 18:55:02
- Last modified 12.04.2025 10:46:40
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authenticat...
CVE-2014-4343
- EPSS 7.38%
- Published 14.08.2014 05:01:49
- Last modified 12.04.2025 10:46:40
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corru...