CVE-2014-2323
- EPSS 92.39%
- Veröffentlicht 14.03.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
- EPSS 73.45%
- Veröffentlicht 14.03.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
CVE-2013-6668
- EPSS 12.82%
- Veröffentlicht 05.03.2014 05:11:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2013-4590
- EPSS 0.22%
- Veröffentlicht 26.02.2014 14:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML d...
- EPSS 25.7%
- Veröffentlicht 18.02.2014 19:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.
CVE-2013-6393
- EPSS 8.06%
- Veröffentlicht 06.02.2014 22:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML docum...
CVE-2014-1487
- EPSS 0.5%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information v...
CVE-2014-1490
- EPSS 1.05%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 11.04.2025 00:51:21
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to ca...
CVE-2014-1491
- EPSS 0.61%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellma...
CVE-2014-1477
- EPSS 0.85%
- Veröffentlicht 06.02.2014 05:44:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and app...