CVE-2014-3917
- EPSS 0.09%
- Published 05.06.2014 17:55:07
- Last modified 12.04.2025 10:46:40
kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a lar...
- EPSS 0.04%
- Published 05.06.2014 17:55:07
- Last modified 12.04.2025 10:46:40
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering...
CVE-2014-0196
- EPSS 69.02%
- Published 07.05.2014 10:55:04
- Last modified 12.04.2025 10:46:40
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or ...
CVE-2014-0150
- EPSS 0.3%
- Published 18.04.2014 14:55:25
- Last modified 12.04.2025 10:46:40
Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest users to execute arbitrary code via a MAC addresses table update request, which triggers a heap-based buffer overflow.
- EPSS 0.12%
- Published 01.04.2014 06:35:52
- Last modified 12.04.2025 10:46:40
Buffer overflow in hw/scsi-disk.c in the SCSI subsystem in QEMU before 0.15.2, as used by Xen, might allow local guest users with permission to access the CD-ROM to cause a denial of service (guest crash) via a crafted SAI READ CAPACITY SCSI command....
CVE-2013-7347
- EPSS 0.14%
- Published 31.03.2014 14:58:45
- Last modified 12.04.2025 10:46:40
Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to gain access to the session by reading the __ac session cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-201...
CVE-2012-3359
- EPSS 0.14%
- Published 31.03.2014 14:58:43
- Last modified 12.04.2025 10:46:40
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the __ac session cookie, which allows attackers to gain privileges by accessing this cookie. NOTE: this issue has been SPLIT due to different vulnerability t...
CVE-2014-0055
- EPSS 0.31%
- Published 26.03.2014 14:55:04
- Last modified 12.04.2025 10:46:40
The get_rx_bufs function in drivers/vhost/net.c in the vhost-net subsystem in the Linux kernel package before 2.6.32-431.11.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle vhost_get_vq_desc errors, which allows guest OS users to cause...
CVE-2011-4111
- EPSS 0.8%
- Published 26.02.2014 15:55:08
- Last modified 12.04.2025 10:46:40
Buffer overflow in the ccid_card_vscard_handle_message function in hw/ccid-card-passthru.c in QEMU before 0.15.2 and 1.x before 1.0-rc4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted VSC...
CVE-2014-0081
- EPSS 0.89%
- Published 20.02.2014 15:27:09
- Last modified 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML ...