CVE-2014-4344
- EPSS 6.99%
- Published 14.08.2014 05:01:49
- Last modified 12.04.2025 10:46:40
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) ...
- EPSS 12.61%
- Published 20.07.2014 11:12:50
- Last modified 12.04.2025 10:46:40
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.
- EPSS 7.31%
- Published 20.07.2014 11:12:50
- Last modified 12.04.2025 10:46:40
MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer dereference, and application crash) by injecting invalid tokens into a GSSAPI application session.
- EPSS 7.12%
- Published 03.07.2014 17:55:05
- Last modified 12.04.2025 10:46:40
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
CVE-2014-4652
- EPSS 0.05%
- Published 03.07.2014 04:22:15
- Last modified 12.04.2025 10:46:40
Race condition in the tlv handler functionality in the snd_ctl_elem_user_tlv function in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allows local users to obtain sensitive information from kernel memory b...
CVE-2014-4656
- EPSS 0.08%
- Published 03.07.2014 04:22:15
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in sound/core/control.c in the ALSA control implementation in the Linux kernel before 3.15.2 allow local users to cause a denial of service by leveraging /dev/snd/controlCX access, related to (1) index values in the snd_ctl...
CVE-2014-4038
- EPSS 0.06%
- Published 17.06.2014 15:55:06
- Last modified 12.04.2025 10:46:40
ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_support.c and /tmp/get_dt_files, (2) scripts/ppc64_diag_mkrsrc and /tmp/diagSEsnap/snapH.tar.gz, or (3) lpd/test/lpd_ela_test.sh and /...
CVE-2014-4039
- EPSS 0.06%
- Published 17.06.2014 15:55:06
- Last modified 12.04.2025 10:46:40
ppc64-diag 2.6.1 uses 0775 permissions for /tmp/diagSEsnap and does not properly restrict permissions for /tmp/diagSEsnap/snapH.tar.gz, which allows local users to obtain sensitive information by reading files in this archive, as demonstrated by /var...
- EPSS 6.62%
- Published 05.06.2014 20:55:06
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
CVE-2014-3468
- EPSS 6.27%
- Published 05.06.2014 20:55:06
- Last modified 12.04.2025 10:46:40
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.