- EPSS 76.31%
- Veröffentlicht 18.08.2014 11:15:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the number of elements in an XML document, which allows remote attackers to cause a denial of service (CPU consumption...
CVE-2014-5204
- EPSS 0.23%
- Veröffentlicht 18.08.2014 11:15:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
wp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in the nonce are incorrect, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a b...
CVE-2014-4343
- EPSS 7.38%
- Veröffentlicht 14.08.2014 05:01:49
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (memory corru...
CVE-2014-4344
- EPSS 5.27%
- Veröffentlicht 14.08.2014 05:01:49
- Zuletzt bearbeitet 12.04.2025 10:46:40
The acc_ctx_cont function in the SPNEGO acceptor in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) ...
CVE-2014-3165
- EPSS 1.74%
- Veröffentlicht 13.08.2014 04:57:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in modules/websockets/WorkerThreadableWebSocketChannel.cpp in the Web Sockets implementation in Blink, as used in Google Chrome before 36.0.1985.143, allows remote attackers to cause a denial of service or possibly have u...
CVE-2014-3166
- EPSS 1.18%
- Veröffentlicht 13.08.2014 04:57:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Public Key Pinning (PKP) implementation in Google Chrome before 36.0.1985.143 on Windows, OS X, and Linux, and before 36.0.1985.135 on Android, does not correctly consider the properties of SPDY connections, which allows remote attackers to obtai...
CVE-2014-3167
- EPSS 0.53%
- Veröffentlicht 13.08.2014 04:57:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.143 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2014-3534
- EPSS 0.07%
- Veröffentlicht 01.08.2014 11:13:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory lo...
CVE-2014-1557
- EPSS 2.43%
- Veröffentlicht 23.07.2014 11:12:43
- Zuletzt bearbeitet 25.11.2025 17:50:16
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attacke...
- EPSS 0.54%
- Veröffentlicht 22.07.2014 14:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensi...