- EPSS 1.67%
- Published 18.11.2014 15:59:01
- Last modified 12.04.2025 10:46:40
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
- EPSS 1.34%
- Published 18.11.2014 15:59:00
- Last modified 12.04.2025 10:46:40
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a s...
CVE-2014-4461
- EPSS 1.86%
- Published 18.11.2014 11:59:08
- Last modified 12.04.2025 10:46:40
The kernel in Apple iOS before 8.1.1 and Apple TV before 7.0.2 does not properly validate IOSharedDataQueue object metadata, which allows attackers to execute arbitrary code in a privileged context via a crafted application.
CVE-2014-4460
- EPSS 0.07%
- Published 18.11.2014 11:59:07
- Last modified 12.04.2025 10:46:40
CFNetwork in Apple iOS before 8.1.1 and OS X before 10.10.1 does not properly clear the browsing cache upon a transition out of private-browsing mode, which makes it easier for physically proximate attackers to obtain sensitive information by reading...
CVE-2014-4459
- EPSS 2.97%
- Published 18.11.2014 11:59:06
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in WebKit, as used in Apple OS X before 10.10.1, allows remote attackers to execute arbitrary code via crafted page objects in an HTML document.
- EPSS 0.56%
- Published 18.11.2014 11:59:05
- Last modified 12.04.2025 10:46:40
The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might allow remote attackers to obtain sensitive information via unspecified vectors.
- EPSS 0.78%
- Published 18.11.2014 11:59:02
- Last modified 12.04.2025 10:46:40
Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight or Safari, which might allow remote attackers to obtain sensitive information via unspecified vectors.
CVE-2014-8517
- EPSS 85.18%
- Published 17.11.2014 16:59:05
- Last modified 12.04.2025 10:46:40
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe) character at the end of an H...
CVE-2014-3707
- EPSS 0.26%
- Published 15.11.2014 20:59:00
- Last modified 12.04.2025 10:46:40
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to r...
- EPSS 5.38%
- Published 04.11.2014 16:55:06
- Last modified 12.04.2025 10:46:40
parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing...