CVE-2010-5312
- EPSS 5.21%
- Veröffentlicht 24.11.2014 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
CVE-2014-9030
- EPSS 1.76%
- Veröffentlicht 24.11.2014 15:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMU_MACHPHYS_UPDATE.
- EPSS 79.79%
- Veröffentlicht 24.11.2014 15:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.
CVE-2014-9015
- EPSS 1.91%
- Veröffentlicht 24.11.2014 15:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.
CVE-2014-7817
- EPSS 0.16%
- Veröffentlicht 24.11.2014 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
CVE-2014-8595
- EPSS 0.07%
- Veröffentlicht 19.11.2014 18:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJM...
CVE-2014-8594
- EPSS 1.42%
- Veröffentlicht 19.11.2014 18:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by leveraging hardware emulation ser...
CVE-2014-7824
- EPSS 0.09%
- Veröffentlicht 18.11.2014 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vu...
- EPSS 3.45%
- Veröffentlicht 15.11.2014 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that tr...
CVE-2014-3707
- EPSS 0.37%
- Veröffentlicht 15.11.2014 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to r...