CVE-2014-3145
- EPSS 0.06%
- Published 11.05.2014 21:55:06
- Last modified 12.04.2025 10:46:40
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read...
CVE-2014-1737
- EPSS 0.07%
- Published 11.05.2014 21:55:05
- Last modified 12.04.2025 10:46:40
The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges b...
CVE-2014-1738
- EPSS 0.03%
- Published 11.05.2014 21:55:05
- Last modified 12.04.2025 10:46:40
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from...
CVE-2014-0196
- EPSS 69.02%
- Published 07.05.2014 10:55:04
- Last modified 12.04.2025 10:46:40
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or ...
CVE-2014-0198
- EPSS 30.89%
- Published 06.05.2014 10:44:05
- Last modified 12.04.2025 10:46:40
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL...
CVE-2014-1530
- EPSS 0.87%
- Published 30.04.2014 10:49:05
- Last modified 12.04.2025 10:46:40
The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-si...
CVE-2014-1531
- EPSS 5.09%
- Published 30.04.2014 10:49:05
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary co...
CVE-2014-1532
- EPSS 4.89%
- Published 30.04.2014 10:49:05
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute a...
CVE-2014-1518
- EPSS 2.82%
- Published 30.04.2014 10:49:04
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and app...
CVE-2014-1523
- EPSS 0.54%
- Published 30.04.2014 10:49:04
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and applicat...