CVE-2014-8594
- EPSS 1.88%
- Veröffentlicht 19.11.2014 18:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by leveraging hardware emulation ser...
- EPSS 0.27%
- Veröffentlicht 18.11.2014 23:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, al...
CVE-2014-0250
- EPSS 3.07%
- Veröffentlicht 16.11.2014 17:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to the (1) xf_Pointer_New or (2) xf_Bitmap_Decompress function, which causes an incorrect amount of memory...
CVE-2014-3707
- EPSS 0.26%
- Veröffentlicht 15.11.2014 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to r...
- EPSS 0.81%
- Veröffentlicht 13.11.2014 21:32:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptograp...
CVE-2014-8559
- EPSS 0.06%
- Veröffentlicht 10.11.2014 11:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
CVE-2014-6300
- EPSS 0.27%
- Veröffentlicht 08.11.2014 11:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the micro history implementation in phpMyAdmin 4.0.x before 4.0.10.3, 4.1.x before 4.1.14.4, and 4.2.x before 4.2.8.1 allows remote attackers to inject arbitrary web script or HTML, and consequently conduct...
CVE-2014-7818
- EPSS 0.3%
- Veröffentlicht 08.11.2014 11:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, al...
CVE-2014-3693
- EPSS 5.36%
- Veröffentlicht 07.11.2014 19:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP p...
- EPSS 3.72%
- Veröffentlicht 06.11.2014 15:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a malformed string.