CVE-2014-8326
- EPSS 0.27%
- Veröffentlicht 05.11.2014 11:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.5, 4.1.x before 4.1.14.6, and 4.2.x before 4.2.10.1 allow remote authenticated users to inject arbitrary web script or HTML via a crafted (1) database name or (2) t...
CVE-2013-4540
- EPSS 3.84%
- Veröffentlicht 04.11.2014 21:55:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.
- EPSS 10.78%
- Veröffentlicht 03.11.2014 16:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1.4 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document, aka an XML Entity Expansion (XEE) attack.
CVE-2014-3615
- EPSS 0.09%
- Veröffentlicht 01.11.2014 23:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
CVE-2014-3474
- EPSS 0.3%
- Veröffentlicht 31.10.2014 15:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users ...
CVE-2014-3475
- EPSS 0.36%
- Veröffentlicht 31.10.2014 15:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user...
CVE-2014-3473
- EPSS 0.4%
- Veröffentlicht 31.10.2014 15:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in the Horizon Orchestration dashboard in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2, when used with Heat, allows remote Or...
- EPSS 0.5%
- Veröffentlicht 31.10.2014 14:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
CVE-2014-3694
- EPSS 1.27%
- Veröffentlicht 29.10.2014 10:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows m...
CVE-2014-3636
- EPSS 0.09%
- Veröffentlicht 25.10.2014 20:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service ...