CVE-2014-5270
- EPSS 0.07%
- Published 10.10.2014 01:55:10
- Last modified 12.04.2025 10:46:40
Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the...
- EPSS 2.82%
- Published 07.10.2014 14:55:08
- Last modified 12.04.2025 10:46:40
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
CVE-2014-6054
- EPSS 40.57%
- Published 06.10.2014 14:55:11
- Last modified 12.04.2025 10:46:40
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) Palm...
CVE-2014-7154
- EPSS 0.91%
- Published 02.10.2014 14:55:05
- Last modified 12.04.2025 10:46:40
Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.
CVE-2014-7155
- EPSS 0.78%
- Published 02.10.2014 14:55:05
- Last modified 12.04.2025 10:46:40
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges ...
CVE-2014-6051
- EPSS 6.61%
- Published 30.09.2014 16:55:07
- Last modified 12.04.2025 10:46:40
Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which...
CVE-2014-6055
- EPSS 11.16%
- Published 30.09.2014 16:55:07
- Last modified 12.04.2025 10:46:40
Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) d...
- EPSS 90.11%
- Published 25.09.2014 01:55:04
- Last modified 12.04.2025 10:46:40
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 94.22%
- Published 24.09.2014 18:48:04
- Last modified 12.04.2025 10:46:40
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
- EPSS 18.47%
- Published 04.09.2014 17:55:07
- Last modified 12.04.2025 10:46:40
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.