CVE-2014-7817
- EPSS 0.17%
- Published 24.11.2014 15:59:01
- Last modified 12.04.2025 10:46:40
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
CVE-2014-8595
- EPSS 0.07%
- Published 19.11.2014 18:59:11
- Last modified 12.04.2025 10:46:40
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJM...
CVE-2014-8594
- EPSS 1.88%
- Published 19.11.2014 18:59:10
- Last modified 12.04.2025 10:46:40
The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by leveraging hardware emulation ser...
CVE-2014-7824
- EPSS 0.1%
- Published 18.11.2014 15:59:04
- Last modified 12.04.2025 10:46:40
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vu...
- EPSS 3.45%
- Published 15.11.2014 20:59:01
- Last modified 12.04.2025 10:46:40
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that tr...
CVE-2014-3707
- EPSS 0.26%
- Published 15.11.2014 20:59:00
- Last modified 12.04.2025 10:46:40
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to r...
- EPSS 5.23%
- Published 14.11.2014 15:59:01
- Last modified 12.04.2025 10:46:40
The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
CVE-2014-3689
- EPSS 0.09%
- Published 14.11.2014 15:59:00
- Last modified 12.04.2025 10:46:40
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
CVE-2014-8369
- EPSS 0.08%
- Published 10.11.2014 11:55:08
- Last modified 12.04.2025 10:46:40
The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or p...
CVE-2014-3690
- EPSS 0.01%
- Published 10.11.2014 11:55:07
- Last modified 12.04.2025 10:46:40
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or caus...