- EPSS 13.65%
- Veröffentlicht 18.12.2014 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does n...
CVE-2014-5353
- EPSS 0.65%
- Veröffentlicht 16.12.2014 23:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via...
- EPSS 1.48%
- Veröffentlicht 16.12.2014 18:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
CVE-2014-9057
- EPSS 0.36%
- Veröffentlicht 16.12.2014 18:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2013-6435
- EPSS 5.09%
- Veröffentlicht 16.12.2014 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the...
- EPSS 36.87%
- Veröffentlicht 15.12.2014 18:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memor...
CVE-2014-6052
- EPSS 5.24%
- Veröffentlicht 15.12.2014 18:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitra...
CVE-2014-8602
- EPSS 7.56%
- Veröffentlicht 11.12.2014 02:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
- EPSS 0.76%
- Veröffentlicht 10.12.2014 15:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
PowerDNS Recursor before 3.6.2 does not limit delegation chaining, which allows remote attackers to cause a denial of service ("performance degradations") via a large or infinite number of referrals, as demonstrated by resolving domains hosted by ezd...
CVE-2014-8102
- EPSS 1.12%
- Veröffentlicht 10.12.2014 15:59:14
- Zuletzt bearbeitet 29.08.2025 13:42:30
The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of...