- EPSS 4.46%
- Veröffentlicht 04.11.2014 16:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing...
- EPSS 10.78%
- Veröffentlicht 03.11.2014 16:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.
CVE-2014-3566
- EPSS 93.73%
- Veröffentlicht 15.10.2014 00:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
- EPSS 89.61%
- Veröffentlicht 25.09.2014 01:55:04
- Zuletzt bearbeitet 22.10.2025 01:16:04
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 94.22%
- Veröffentlicht 24.09.2014 18:48:04
- Zuletzt bearbeitet 22.10.2025 01:15:57
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
- EPSS 0.31%
- Veröffentlicht 21.08.2014 14:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.
CVE-2014-3560
- EPSS 74.28%
- Veröffentlicht 06.08.2014 18:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
NetBIOS name services daemon (nmbd) in Samba 4.0.x before 4.0.21 and 4.1.x before 4.1.11 allows remote attackers to execute arbitrary code via unspecified vectors that modify heap memory, involving a sizeof operation on an incorrect variable in the u...
CVE-2014-0179
- EPSS 0.11%
- Veröffentlicht 03.08.2014 18:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompa...
CVE-2014-5177
- EPSS 0.11%
- Veröffentlicht 03.08.2014 18:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the ...
CVE-2014-2483
- EPSS 7.17%
- Veröffentlicht 17.07.2014 05:10:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in the Java SE component in Oracle Java SE Java SE 7u60 and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CV...