CVE-2014-8104
- EPSS 1.47%
- Veröffentlicht 03.12.2014 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.
CVE-2014-9220
- EPSS 0.44%
- Veröffentlicht 03.12.2014 01:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command.
CVE-2014-8867
- EPSS 0.13%
- Veröffentlicht 01.12.2014 15:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The acceleration support for the "REP MOVS" instruction in Xen 4.4.x, 3.2.x, and earlier lacks properly bounds checking for memory mapped I/O (MMIO) emulated in the hypervisor, which allows local HVM guests to cause a denial of service (host crash) v...
CVE-2014-8866
- EPSS 0.09%
- Veröffentlicht 01.12.2014 15:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The compatibility mode hypercall argument translation in Xen 3.3.x through 4.4.x, when running on a 64-bit hypervisor, allows local 32-bit HVM guests to cause a denial of service (host crash) via vectors involving altering the high halves of register...
- EPSS 1.99%
- Veröffentlicht 30.11.2014 11:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in libraries/error_report.lib.php in the error-reporting feature in phpMyAdmin 4.1.x before 4.1.14.7 and 4.2.x before 4.2.12 allows remote authenticated users to obtain potentially sensitive information about a file'...
CVE-2014-8959
- EPSS 3.72%
- Veröffentlicht 30.11.2014 11:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in libraries/gis/GIS_Factory.class.php in the GIS editor in phpMyAdmin 4.0.x before 4.0.10.6, 4.1.x before 4.1.14.7, and 4.2.x before 4.2.12 allows remote authenticated users to include and execute arbitrary local fi...
CVE-2014-9030
- EPSS 2.32%
- Veröffentlicht 24.11.2014 15:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMU_MACHPHYS_UPDATE.
CVE-2014-7817
- EPSS 0.17%
- Veröffentlicht 24.11.2014 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
- EPSS 28.31%
- Veröffentlicht 20.11.2014 17:50:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.
CVE-2014-8595
- EPSS 0.07%
- Veröffentlicht 19.11.2014 18:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJM...