CVE-2014-5119
- EPSS 13.42%
- Published 29.08.2014 16:55:11
- Last modified 12.04.2025 10:46:40
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment vari...
CVE-2014-3168
- EPSS 1.56%
- Published 27.08.2014 01:55:05
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper caching associated wi...
CVE-2014-3169
- EPSS 3.25%
- Published 27.08.2014 01:55:05
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging ...
CVE-2014-0481
- EPSS 1.49%
- Published 26.08.2014 14:55:05
- Last modified 12.04.2025 10:46:40
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is up...
CVE-2014-5240
- EPSS 0.63%
- Published 18.08.2014 11:15:27
- Last modified 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a cr...
- EPSS 7.02%
- Published 18.08.2014 11:15:27
- Last modified 12.04.2025 10:46:40
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of...
- EPSS 76.31%
- Published 18.08.2014 11:15:27
- Last modified 12.04.2025 10:46:40
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption...
CVE-2014-5204
- EPSS 0.23%
- Published 18.08.2014 11:15:26
- Last modified 12.04.2025 10:46:40
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a b...
CVE-2014-4343
- EPSS 7.38%
- Published 14.08.2014 05:01:49
- Last modified 12.04.2025 10:46:40
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corru...
CVE-2014-4344
- EPSS 6.99%
- Published 14.08.2014 05:01:49
- Last modified 12.04.2025 10:46:40
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) ...