- EPSS 0.44%
- Veröffentlicht 03.09.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or...
- EPSS 1.15%
- Veröffentlicht 03.09.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of servi...
CVE-2014-1564
- EPSS 15.41%
- Veröffentlicht 03.09.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 do not properly initialize memory for GIF rendering, which allows remote attackers to obtain sensitive information from process memory via crafted web script ...
CVE-2014-3168
- EPSS 1.56%
- Veröffentlicht 27.08.2014 01:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper caching associated wi...
CVE-2014-3169
- EPSS 3.25%
- Veröffentlicht 27.08.2014 01:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging ...
CVE-2014-0480
- EPSS 0.56%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The core.urlresolvers.reverse function in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not properly validate URLs, which allows remote attackers to conduct phishing attacks via a // (slash slas...
CVE-2014-0481
- EPSS 1.49%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is up...
- EPSS 0.71%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The contrib.auth.middleware.RemoteUserMiddleware middleware in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3, when using the contrib.auth.backends.RemoteUserBackend backend, allows remote authenticat...
CVE-2014-0483
- EPSS 0.43%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The administrative interface (contrib.admin) in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 does not check if a field represents a relationship between models, which allows remote authenticated use...
CVE-2014-2527
- EPSS 0.95%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
kcleanup.cpp in KDirStat 2.7.0 does not properly quote strings when deleting a directory, which allows remote attackers to execute arbitrary commands via a " (double quote) character in the directory name, a different vulnerability than CVE-2014-2528...