CVE-2014-6568
- EPSS 2.94%
- Veröffentlicht 21.01.2015 15:28:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
CVE-2014-9585
- EPSS 0.05%
- Veröffentlicht 09.01.2015 21:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the ...
CVE-2014-9584
- EPSS 0.13%
- Veröffentlicht 09.01.2015 21:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel...
CVE-2014-9529
- EPSS 0.11%
- Veröffentlicht 09.01.2015 21:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that...
CVE-2014-5353
- EPSS 0.55%
- Veröffentlicht 16.12.2014 23:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via...
- EPSS 2.06%
- Veröffentlicht 16.12.2014 18:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.
CVE-2014-8567
- EPSS 3.6%
- Veröffentlicht 14.11.2014 15:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.
CVE-2014-3615
- EPSS 0.09%
- Veröffentlicht 01.11.2014 23:55:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
- EPSS 4.81%
- Veröffentlicht 10.10.2014 10:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP...
- EPSS 89.06%
- Veröffentlicht 25.09.2014 01:55:04
- Zuletzt bearbeitet 22.04.2026 14:32:42
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...