CVE-2014-3917
- EPSS 0.09%
- Veröffentlicht 05.06.2014 17:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a lar...
CVE-2014-1737
- EPSS 0.07%
- Veröffentlicht 11.05.2014 21:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges b...
CVE-2014-1738
- EPSS 0.03%
- Veröffentlicht 11.05.2014 21:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from...
CVE-2014-0198
- EPSS 30.89%
- Veröffentlicht 06.05.2014 10:44:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL...
- EPSS 14.64%
- Veröffentlicht 14.04.2014 22:38:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via...
CVE-2014-1494
- EPSS 0.49%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via u...
- EPSS 0.55%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger gene...
CVE-2014-1499
- EPSS 0.61%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
- EPSS 2.26%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.
CVE-2014-1501
- EPSS 0.23%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.