CVE-2014-8150
- EPSS 1.23%
- Veröffentlicht 15.01.2015 15:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
- EPSS 0.62%
- Veröffentlicht 10.01.2015 02:59:42
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer underflow in the ssl_decrypt_record function in epan/dissectors/packet-ssl-utils.c in Wireshark 1.10.x before 1.10.12 and 1.12.x before 1.12.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet that i...
CVE-2014-9585
- EPSS 0.05%
- Veröffentlicht 09.01.2015 21:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the ...
CVE-2014-9584
- EPSS 0.13%
- Veröffentlicht 09.01.2015 21:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel...
CVE-2014-9529
- EPSS 0.11%
- Veröffentlicht 09.01.2015 21:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that...
CVE-2014-9272
- EPSS 0.44%
- Veröffentlicht 09.01.2015 18:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The string_insert_href function in MantisBT 1.2.0a1 through 1.2.x before 1.2.18 does not properly validate the URL protocol, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the javascript:// protocol.
CVE-2014-9271
- EPSS 0.83%
- Veröffentlicht 09.01.2015 18:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in file_download.php in MantisBT before 1.2.18 allows remote authenticated users to inject arbitrary web script or HTML via a Flash file with an image extension, related to inline attachments, as demonstrated ...
CVE-2014-9269
- EPSS 0.41%
- Veröffentlicht 09.01.2015 18:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x before 1.2.18, when Extended project browser is enabled, allows remote attackers to inject arbitrary web script or HTML via the project cookie.
CVE-2012-6684
- EPSS 0.59%
- Veröffentlicht 08.01.2015 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.
- EPSS 6.86%
- Veröffentlicht 07.01.2015 19:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.