CVE-2014-4616
- EPSS 0.43%
- Veröffentlicht 24.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decod...
CVE-2014-0481
- EPSS 1.49%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is up...
CVE-2014-3004
- EPSS 0.78%
- Veröffentlicht 11.06.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The default configuration for the Xerces SAX Parser in Castor before 1.3.3 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XML document.
CVE-2014-1542
- EPSS 4.72%
- Veröffentlicht 11.06.2014 10:57:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the Speex resampler in the Web Audio subsystem in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code via vectors related to a crafted AudioBuffer channel count and sample rate.
- EPSS 1.12%
- Veröffentlicht 30.04.2014 10:49:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by...
CVE-2014-1494
- EPSS 0.49%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via u...
- EPSS 0.55%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger gene...
CVE-2014-1499
- EPSS 0.61%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
- EPSS 2.26%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.
CVE-2014-1502
- EPSS 0.28%
- Veröffentlicht 19.03.2014 10:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecifi...