CVE-2014-5459
- EPSS 0.08%
- Veröffentlicht 27.09.2014 10:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The PEAR_REST class in REST.php in PEAR in PHP through 5.6.0 allows local users to write to arbitrary files via a symlink attack on a (1) rest.cachefile or (2) rest.cacheid file in /tmp/pear/cache/, related to the retrieveCacheFirst and useLocalCache...
- EPSS 90.11%
- Veröffentlicht 25.09.2014 01:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 94.22%
- Veröffentlicht 24.09.2014 18:48:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
CVE-2014-3637
- EPSS 0.07%
- Veröffentlicht 22.09.2014 15:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descri...
CVE-2014-3638
- EPSS 0.1%
- Veröffentlicht 22.09.2014 15:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls.
CVE-2014-3639
- EPSS 0.09%
- Veröffentlicht 22.09.2014 15:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connections) via a large number of i...
CVE-2014-3635
- EPSS 0.17%
- Veröffentlicht 22.09.2014 15:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or pos...
- EPSS 1.67%
- Veröffentlicht 11.09.2014 18:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that trigger an out-of-bounds read.
- EPSS 1.62%
- Veröffentlicht 10.09.2014 01:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR...
- EPSS 18.47%
- Veröffentlicht 04.09.2014 17:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.