- EPSS 94.22%
- Veröffentlicht 24.09.2014 18:48:04
- Zuletzt bearbeitet 22.04.2026 16:07:22
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
CVE-2014-0207
- EPSS 9.15%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a craft...
CVE-2014-3479
- EPSS 14.8%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (appli...
CVE-2014-3480
- EPSS 8.15%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (appli...
CVE-2014-3487
- EPSS 14.5%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (applicati...
CVE-2014-0203
- EPSS 0.07%
- Veröffentlicht 23.06.2014 11:21:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and...
CVE-2014-3153
- EPSS 68.89%
- Veröffentlicht 07.06.2014 14:55:27
- Zuletzt bearbeitet 21.04.2026 17:47:00
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe wai...
CVE-2014-3144
- EPSS 0.06%
- Veröffentlicht 11.05.2014 21:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficiently large, which allows loc...
CVE-2014-3145
- EPSS 0.06%
- Veröffentlicht 11.05.2014 21:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read...
CVE-2014-1737
- EPSS 0.05%
- Veröffentlicht 11.05.2014 21:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges b...