CVE-2014-1479
- EPSS 1.47%
- Veröffentlicht 06.02.2014 05:44:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intende...
CVE-2014-1481
- EPSS 2.58%
- Veröffentlicht 06.02.2014 05:44:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across differe...
CVE-2014-1482
- EPSS 2.74%
- Veröffentlicht 06.02.2014 05:44:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of s...
- EPSS 10.82%
- Veröffentlicht 06.02.2014 05:44:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unsp...
CVE-2011-4613
- EPSS 0.08%
- Veröffentlicht 05.02.2014 19:55:28
- Zuletzt bearbeitet 11.04.2025 00:51:21
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misint...
CVE-2013-4449
- EPSS 68.75%
- Veröffentlicht 05.02.2014 18:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to f...
CVE-2013-6650
- EPSS 2.38%
- Veröffentlicht 28.01.2014 14:30:39
- Zuletzt bearbeitet 11.04.2025 00:51:21
The StoreBuffer::ExemptPopularPages function in store-buffer.cc in Google V8 before 3.22.24.16, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other...
CVE-2013-6649
- EPSS 0.93%
- Veröffentlicht 28.01.2014 14:30:33
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified oth...
CVE-2013-0339
- EPSS 2.39%
- Veröffentlicht 21.01.2014 18:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource cons...
- EPSS 3%
- Veröffentlicht 18.01.2014 19:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer underflow in the pixman_trapezoid_valid macro in pixman.h in Pixman before 0.32.0, as used in X.Org server and cairo, allows context-dependent attackers to cause a denial of service (crash) via a negative bottom value.