CVE-2014-8145
- EPSS 13%
- Veröffentlicht 31.12.2014 22:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function.
- EPSS 2.78%
- Veröffentlicht 29.12.2014 00:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.
- EPSS 13.65%
- Veröffentlicht 18.12.2014 15:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does n...
CVE-2014-5353
- EPSS 0.55%
- Veröffentlicht 16.12.2014 23:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via...
- EPSS 1.48%
- Veröffentlicht 16.12.2014 18:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
CVE-2014-9057
- EPSS 0.36%
- Veröffentlicht 16.12.2014 18:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
SQL injection vulnerability in the XML-RPC interface in Movable Type before 5.18, 5.2.x before 5.2.11, and 6.x before 6.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2013-6435
- EPSS 5.09%
- Veröffentlicht 16.12.2014 18:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in RPM 4.11.1 and earlier allows remote attackers to execute arbitrary code via a crafted RPM file whose installation extracts the contents to temporary files before validating the signature, as demonstrated by installing a file in the...
- EPSS 36.87%
- Veröffentlicht 15.12.2014 18:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memor...
CVE-2014-6052
- EPSS 4.54%
- Veröffentlicht 15.12.2014 18:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitra...
CVE-2014-8602
- EPSS 7.56%
- Veröffentlicht 11.12.2014 02:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.