CVE-2014-3480
- EPSS 11.28%
- Published 09.07.2014 11:07:01
- Last modified 12.04.2025 10:46:40
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (appli...
CVE-2014-3487
- EPSS 18.5%
- Published 09.07.2014 11:07:01
- Last modified 12.04.2025 10:46:40
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (applicati...
CVE-2014-0203
- EPSS 0.04%
- Published 23.06.2014 11:21:17
- Last modified 12.04.2025 10:46:40
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and...
CVE-2014-3153
- EPSS 79.92%
- Published 07.06.2014 14:55:27
- Last modified 12.04.2025 10:46:40
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe wai...
CVE-2014-3144
- EPSS 0.06%
- Published 11.05.2014 21:55:06
- Last modified 12.04.2025 10:46:40
The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficiently large, which allows loc...
CVE-2014-3145
- EPSS 0.06%
- Published 11.05.2014 21:55:06
- Last modified 12.04.2025 10:46:40
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read...
CVE-2014-1737
- EPSS 0.07%
- Published 11.05.2014 21:55:05
- Last modified 12.04.2025 10:46:40
The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges b...
CVE-2014-1738
- EPSS 0.03%
- Published 11.05.2014 21:55:05
- Last modified 12.04.2025 10:46:40
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from...
CVE-2014-0196
- EPSS 69.02%
- Published 07.05.2014 10:55:04
- Last modified 12.04.2025 10:46:40
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or ...
- EPSS 75.57%
- Published 15.04.2014 10:55:11
- Last modified 12.04.2025 10:46:40
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a s...