CVE-2004-2771
- EPSS 6.86%
- Veröffentlicht 24.12.2014 18:59:00
- Zuletzt bearbeitet 23.09.2026 13:10:00
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.
CVE-2014-8867
- EPSS 0.47%
- Veröffentlicht 01.12.2014 15:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) v...
CVE-2014-3690
- EPSS 0.52%
- Veröffentlicht 10.11.2014 11:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or caus...
CVE-2014-3611
- EPSS 0.29%
- Veröffentlicht 10.11.2014 11:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel through 3.17.2 allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation.
CVE-2014-3646
- EPSS 0.43%
- Veröffentlicht 10.11.2014 11:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
CVE-2014-3647
- EPSS 0.59%
- Veröffentlicht 10.11.2014 11:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
CVE-2014-3673
- EPSS 7.46%
- Veröffentlicht 10.11.2014 11:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c.
- EPSS 3.99%
- Veröffentlicht 04.11.2014 16:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing...
- EPSS 5.54%
- Veröffentlicht 03.11.2014 16:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.
CVE-2014-3566
- EPSS 100%
- Veröffentlicht 15.10.2014 00:55:02
- Zuletzt bearbeitet 28.05.2026 18:16:23
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.