CVE-2014-3487
- EPSS 18.5%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (applicati...
- EPSS 7.12%
- Veröffentlicht 03.07.2014 17:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
CVE-2014-4002
- EPSS 0.43%
- Veröffentlicht 03.07.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drp_action parameter to cdef.php, (2) data_input.php, (3) data_queries.php, (4) data_sources.php, (5) data_t...
CVE-2014-4608
- EPSS 8.66%
- Veröffentlicht 03.07.2014 04:22:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a cra...
CVE-2014-3494
- EPSS 0.18%
- Veröffentlicht 01.07.2014 16:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
kio/usernotificationhandler.cpp in the POP3 kioslave in kdelibs 4.10.95 before 4.13.3 does not properly generate warning notifications, which allows man-in-the-middle attackers to obtain sensitive information via an invalid certificate.
- EPSS 8.03%
- Veröffentlicht 25.06.2014 11:19:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_uncompress function in g10/compress.c in GnuPG 1.x before 1.4.17 and 2.x before 2.0.24 allows context-dependent attackers to cause a denial of service (infinite loop) via malformed compressed packets, as demonstrated by an a3 01 5b ff byte seq...
CVE-2014-4049
- EPSS 22.41%
- Veröffentlicht 18.06.2014 19:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the php_parserr function in ext/standard/dns.c in PHP 5.6.0beta4 and earlier allows remote servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS TXT record, related to the dns...
CVE-2014-4165
- EPSS 0.42%
- Veröffentlicht 16.06.2014 18:55:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in ntop allows remote attackers to inject arbitrary web script or HTML via the title parameter in a list action to plugins/rrdPlugin.
- EPSS 10.2%
- Veröffentlicht 11.06.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo inte...
- EPSS 8.62%
- Veröffentlicht 11.06.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds...