- EPSS 24.2%
- Veröffentlicht 21.02.2014 05:07:00
- Zuletzt bearbeitet 21.04.2026 21:11:58
Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adob...
CVE-2014-0081
- EPSS 4.03%
- Veröffentlicht 20.02.2014 15:27:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML ...
- EPSS 2.73%
- Veröffentlicht 10.02.2014 18:15:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows remote attackers to obtain sensitive information such as server-usage patterns by a particular user a...
CVE-2011-4093
- EPSS 1.76%
- Veröffentlicht 10.02.2014 18:15:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer overflow in inc/server.hpp in libnet6 (aka net6) before 1.3.14 might allow remote attackers to hijack connections and gain privileges as other users by making a large number of connections until the overflow occurs and an ID of another user i...
- EPSS 1.86%
- Veröffentlicht 10.02.2014 18:15:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) before 2.1.12 computes hash values without restricting the ability to trigger hash c...
CVE-2013-2191
- EPSS 0.9%
- Veröffentlicht 08.02.2014 00:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
CVE-2013-6393
- EPSS 7.39%
- Veröffentlicht 06.02.2014 22:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML docum...
CVE-2014-0038
- EPSS 35.45%
- Veröffentlicht 06.02.2014 22:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.
- EPSS 2.93%
- Veröffentlicht 06.02.2014 17:00:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
cpio, as used in build 2007.05.10, 2010.07.28, and possibly other versions, allows remote attackers to overwrite arbitrary files via a symlink within an RPM package archive.
CVE-2012-1095
- EPSS 1.36%
- Veröffentlicht 06.02.2014 17:00:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
osc before 0.134 might allow remote OBS repository servers or package maintainers to execute arbitrary commands via a crafted (1) build log or (2) build status that contains an escape sequence for a terminal emulator.