- EPSS 6.51%
- Veröffentlicht 16.12.2014 18:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.
CVE-2014-7840
- EPSS 4.12%
- Veröffentlicht 12.12.2014 15:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data.
- EPSS 3.74%
- Veröffentlicht 14.11.2014 15:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
CVE-2014-3615
- EPSS 0.45%
- Veröffentlicht 01.11.2014 23:55:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
- EPSS 13.56%
- Veröffentlicht 10.10.2014 10:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP...
- EPSS 99.94%
- Veröffentlicht 25.09.2014 01:55:04
- Zuletzt bearbeitet 22.04.2026 14:32:42
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 100%
- Veröffentlicht 24.09.2014 18:48:04
- Zuletzt bearbeitet 22.04.2026 16:07:22
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
CVE-2014-5045
- EPSS 0.49%
- Veröffentlicht 01.08.2014 11:13:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows local users to cause a denial ...
CVE-2014-5077
- EPSS 5.79%
- Veröffentlicht 01.08.2014 11:13:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The sctp_assoc_update function in net/sctp/associola.c in the Linux kernel through 3.15.8, when SCTP authentication is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by starting to establish an assoc...
- EPSS 7.14%
- Veröffentlicht 20.07.2014 11:12:50
- Zuletzt bearbeitet 06.05.2026 22:30:45
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.