CVE-2014-3429
- EPSS 4.7%
- Veröffentlicht 07.08.2014 11:13:34
- Zuletzt bearbeitet 06.05.2026 22:30:45
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
CVE-2013-4159
- EPSS 2.37%
- Veröffentlicht 06.08.2014 18:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulnerabilities" in (1) tcp/tcp_connect.c, (2) server/eventscript.c, (3) tools/ctdb_diagnostics, (4) config...
CVE-2014-0179
- EPSS 0.56%
- Veröffentlicht 03.08.2014 18:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompa...
CVE-2014-5177
- EPSS 0.53%
- Veröffentlicht 03.08.2014 18:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the ...
- EPSS 1.26%
- Veröffentlicht 20.07.2014 11:12:51
- Zuletzt bearbeitet 06.05.2026 22:30:45
server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.
CVE-2014-3533
- EPSS 0.42%
- Veröffentlicht 19.07.2014 19:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor.
CVE-2014-4943
- EPSS 2.1%
- Veröffentlicht 19.07.2014 19:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
CVE-2014-3532
- EPSS 0.45%
- Veröffentlicht 19.07.2014 19:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, t...
CVE-2014-0207
- EPSS 16.85%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a craft...
CVE-2014-3479
- EPSS 14.93%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (appli...