- EPSS 75.57%
- Veröffentlicht 15.04.2014 10:55:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...
CVE-2014-0160
- EPSS 94.46%
- Veröffentlicht 07.04.2014 22:55:03
- Zuletzt bearbeitet 22.10.2025 01:15:53
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer ov...
CVE-2014-2497
- EPSS 12.14%
- Veröffentlicht 21.03.2014 14:55:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
- EPSS 1.47%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 25.11.2025 17:50:16
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and app...
CVE-2014-1497
- EPSS 0.5%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 25.11.2025 17:50:16
The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause...
CVE-2014-1505
- EPSS 0.54%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 25.11.2025 17:50:16
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the S...
CVE-2014-1508
- EPSS 0.99%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 25.11.2025 17:50:16
The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of...
CVE-2014-1509
- EPSS 0.81%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 25.11.2025 17:50:16
Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a ...
CVE-2014-1510
- EPSS 76.45%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 25.11.2025 17:50:16
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment t...
CVE-2014-1511
- EPSS 75.96%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 25.11.2025 17:50:16
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.