CVE-2014-5119
- EPSS 13.42%
- Veröffentlicht 29.08.2014 16:55:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment vari...
CVE-2014-3168
- EPSS 1.56%
- Veröffentlicht 27.08.2014 01:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper caching associated wi...
CVE-2014-3169
- EPSS 3.25%
- Veröffentlicht 27.08.2014 01:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging ...
CVE-2014-0481
- EPSS 1.49%
- Veröffentlicht 26.08.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The default configuration for the file upload handling system in Django before 1.4.14, 1.5.x before 1.5.9, 1.6.x before 1.6.6, and 1.7 before release candidate 3 uses a sequential file name generation process when a file with a conflicting name is up...
CVE-2014-5240
- EPSS 0.63%
- Veröffentlicht 18.08.2014 11:15:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a cr...
- EPSS 7.02%
- Veröffentlicht 18.08.2014 11:15:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity declarations without considering recursion during entity expansion, which allows remote attackers to cause a denial of...
- EPSS 76.31%
- Veröffentlicht 18.08.2014 11:15:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption...
CVE-2014-5204
- EPSS 0.23%
- Veröffentlicht 18.08.2014 11:15:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a b...
CVE-2014-4343
- EPSS 7.38%
- Veröffentlicht 14.08.2014 05:01:49
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corru...
CVE-2014-4344
- EPSS 6.99%
- Veröffentlicht 14.08.2014 05:01:49
- Zuletzt bearbeitet 12.04.2025 10:46:40
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) ...