CVE-2014-1738
- EPSS 0.02%
- Veröffentlicht 11.05.2014 21:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from...
CVE-2014-0198
- EPSS 32.98%
- Veröffentlicht 06.05.2014 10:44:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL...
CVE-2014-0181
- EPSS 0.03%
- Veröffentlicht 27.04.2014 00:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configura...
- EPSS 14.1%
- Veröffentlicht 14.04.2014 22:38:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via...
CVE-2014-0131
- EPSS 0.1%
- Veröffentlicht 24.03.2014 16:40:48
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
CVE-2014-2497
- EPSS 12.42%
- Veröffentlicht 21.03.2014 14:55:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file.
CVE-2014-1494
- EPSS 0.56%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via u...
- EPSS 0.55%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger gene...
CVE-2014-1499
- EPSS 0.61%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
- EPSS 2.26%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.