- EPSS 3.29%
- Veröffentlicht 29.12.2014 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.
CVE-2014-8136
- EPSS 0.13%
- Veröffentlicht 19.12.2014 15:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
CVE-2014-5353
- EPSS 0.47%
- Veröffentlicht 16.12.2014 23:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via...
- EPSS 2.09%
- Veröffentlicht 16.12.2014 18:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.
CVE-2014-8134
- EPSS 0.08%
- Veröffentlicht 12.12.2014 18:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted ...
- EPSS 0.78%
- Veröffentlicht 12.12.2014 15:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests...
CVE-2014-9066
- EPSS 0.04%
- Veröffentlicht 09.12.2014 23:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read...
CVE-2014-9065
- EPSS 0.07%
- Veröffentlicht 09.12.2014 23:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
common/spinlock.c in Xen 4.4.x and earlier does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a dif...
CVE-2014-9273
- EPSS 0.18%
- Veröffentlicht 08.12.2014 16:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
lib/handle.c in Hivex before 1.3.11 allows local users to execute arbitrary code and gain privileges via a small hive files, which triggers an out-of-bounds read or write.
CVE-2014-8600
- EPSS 0.28%
- Veröffentlicht 08.12.2014 11:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in KDE-Runtime 4.14.3 and earlier, kwebkitpart 1.3.4 and earlier, and kio-extras 5.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via a crafted URI using the (1) zip, ...