CVE-2013-4159
- EPSS 0.62%
- Veröffentlicht 06.08.2014 18:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulnerabilities" in (1) tcp/tcp_connect.c, (2) server/eventscript.c, (3) tools/ctdb_diagnostics, (4) config...
CVE-2014-0179
- EPSS 0.11%
- Veröffentlicht 03.08.2014 18:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompa...
CVE-2014-5177
- EPSS 0.11%
- Veröffentlicht 03.08.2014 18:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the ...
- EPSS 0.19%
- Veröffentlicht 20.07.2014 11:12:51
- Zuletzt bearbeitet 12.04.2025 10:46:40
server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.
CVE-2014-3533
- EPSS 0.08%
- Veröffentlicht 19.07.2014 19:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor.
CVE-2014-4943
- EPSS 1.03%
- Veröffentlicht 19.07.2014 19:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
CVE-2014-3532
- EPSS 0.12%
- Veröffentlicht 19.07.2014 19:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, t...
CVE-2014-0207
- EPSS 8.85%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a craft...
CVE-2014-3479
- EPSS 11.28%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (appli...
CVE-2014-3480
- EPSS 11.28%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (appli...