CVE-2014-7154
- EPSS 0.73%
- Veröffentlicht 02.10.2014 14:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.
CVE-2014-7155
- EPSS 1.03%
- Veröffentlicht 02.10.2014 14:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges ...
CVE-2014-6051
- EPSS 7.98%
- Veröffentlicht 30.09.2014 16:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which...
CVE-2014-6055
- EPSS 11.16%
- Veröffentlicht 30.09.2014 16:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) d...
- EPSS 89.06%
- Veröffentlicht 25.09.2014 01:55:04
- Zuletzt bearbeitet 22.04.2026 14:32:42
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 94.22%
- Veröffentlicht 24.09.2014 18:48:04
- Zuletzt bearbeitet 22.04.2026 16:07:22
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
- EPSS 10.63%
- Veröffentlicht 04.09.2014 17:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
CVE-2014-5119
- EPSS 21.51%
- Veröffentlicht 29.08.2014 16:55:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment vari...
CVE-2014-3168
- EPSS 2.05%
- Veröffentlicht 27.08.2014 01:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the SVG implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper caching associated wi...
CVE-2014-3169
- EPSS 3.25%
- Veröffentlicht 27.08.2014 01:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in core/dom/ContainerNode.cpp in the DOM implementation in Blink, as used in Google Chrome before 37.0.2062.94, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging ...