CVE-2014-4027
- EPSS 0.09%
- Veröffentlicht 23.06.2014 11:21:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveragin...
CVE-2014-4038
- EPSS 0.06%
- Veröffentlicht 17.06.2014 15:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_support.c and /tmp/get_dt_files, (2) scripts/ppc64_diag_mkrsrc and /tmp/diagSEsnap/snapH.tar.gz, or (3) lpd/test/lpd_ela_test.sh and /...
CVE-2014-4039
- EPSS 0.06%
- Veröffentlicht 17.06.2014 15:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
ppc64-diag 2.6.1 uses 0775 permissions for /tmp/diagSEsnap and does not properly restrict permissions for /tmp/diagSEsnap/snapH.tar.gz, which allows local users to obtain sensitive information by reading files in this archive, as demonstrated by /var...
CVE-2014-3153
- EPSS 68.89%
- Veröffentlicht 07.06.2014 14:55:27
- Zuletzt bearbeitet 21.04.2026 17:47:00
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe wai...
CVE-2014-3470
- EPSS 91.4%
- Veröffentlicht 05.06.2014 21:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereferen...
CVE-2014-0221
- EPSS 82.1%
- Veröffentlicht 05.06.2014 21:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS...
- EPSS 6.83%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
CVE-2014-3468
- EPSS 10.74%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
- EPSS 8.67%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
CVE-2014-1737
- EPSS 0.05%
- Veröffentlicht 11.05.2014 21:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges b...