CVE-2014-5077
- EPSS 14.7%
- Veröffentlicht 01.08.2014 11:13:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an assoc...
CVE-2014-4656
- EPSS 0.08%
- Veröffentlicht 03.07.2014 04:22:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (1) index values in the snd_ctl...
- EPSS 6.62%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
CVE-2014-3468
- EPSS 6.27%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
- EPSS 4.68%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
CVE-2014-1530
- EPSS 0.87%
- Veröffentlicht 30.04.2014 10:49:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-si...
CVE-2014-1531
- EPSS 5.09%
- Veröffentlicht 30.04.2014 10:49:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary co...
CVE-2014-1532
- EPSS 4.89%
- Veröffentlicht 30.04.2014 10:49:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute a...
CVE-2014-1518
- EPSS 2.82%
- Veröffentlicht 30.04.2014 10:49:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and app...
CVE-2014-1523
- EPSS 0.54%
- Veröffentlicht 30.04.2014 10:49:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and applicat...