CVE-2014-5025
- EPSS 0.45%
- Veröffentlicht 20.10.2014 17:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.
CVE-2014-5026
- EPSS 0.35%
- Veröffentlicht 20.10.2014 17:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input M...
CVE-2014-2576
- EPSS 0.67%
- Veröffentlicht 15.10.2014 14:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.
- EPSS 0.46%
- Veröffentlicht 15.10.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
- EPSS 7.55%
- Veröffentlicht 15.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attacker...
CVE-2014-0569
- EPSS 89.33%
- Veröffentlicht 15.10.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0....
CVE-2014-3566
- EPSS 94.02%
- Veröffentlicht 15.10.2014 00:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
CVE-2014-4043
- EPSS 1.64%
- Veröffentlicht 06.10.2014 23:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
CVE-2014-7154
- EPSS 0.91%
- Veröffentlicht 02.10.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.
CVE-2014-7155
- EPSS 0.78%
- Veröffentlicht 02.10.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges ...