CVE-2014-3004
- EPSS 0.78%
- Veröffentlicht 11.06.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.
CVE-2014-1542
- EPSS 4.72%
- Veröffentlicht 11.06.2014 10:57:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rate.
CVE-2014-3153
- EPSS 80.51%
- Veröffentlicht 07.06.2014 14:55:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe wai...
CVE-2014-0224
- EPSS 92.69%
- Veröffentlicht 05.06.2014 21:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL...
CVE-2014-3470
- EPSS 91.4%
- Veröffentlicht 05.06.2014 21:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereferen...
CVE-2014-0195
- EPSS 90.91%
- Veröffentlicht 05.06.2014 21:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary c...
CVE-2014-0221
- EPSS 82.1%
- Veröffentlicht 05.06.2014 21:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS...
CVE-2014-3967
- EPSS 0.27%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x does not properly check the return value from the IRQ setup check, which allows local HVM guest administrators to cause a denial of service (NULL pointer dereference and crash) via unspecif...
CVE-2014-3968
- EPSS 0.41%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HVMOP_inject_msi function in Xen 4.2.x, 4.3.x, and 4.4.x allows local guest HVM administrators to cause a denial of service (host crash) via a large number of crafted requests, which trigger an error messages to be logged.
CVE-2011-2198
- EPSS 0.81%
- Veröffentlicht 21.05.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The "insert-blank-characters" capability in caps.c in gnome-terminal (vte) before 0.28.1 allows remote authenticated users to cause a denial of service (CPU and memory consumption and crash) via a crafted file, as demonstrated by a file containing th...