CVE-2014-3468
- EPSS 10.74%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data.
- EPSS 8.67%
- Veröffentlicht 05.06.2014 20:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument.
- EPSS 30.7%
- Veröffentlicht 01.06.2014 04:29:34
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cdf_unpack_summary_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (performance degradation) by triggering many file_printf calls.
- EPSS 40.64%
- Veröffentlicht 01.06.2014 04:29:34
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cdf_read_property_info function in cdf.c in the Fileinfo component in PHP before 5.4.29 and 5.5.x before 5.5.13 allows remote attackers to cause a denial of service (infinite loop or out-of-bounds memory access) via a vector that (1) has zero len...
CVE-2014-3730
- EPSS 0.99%
- Veröffentlicht 16.05.2014 15:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as de...
CVE-2014-3122
- EPSS 0.09%
- Veröffentlicht 11.05.2014 21:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that req...
CVE-2014-3144
- EPSS 0.06%
- Veröffentlicht 11.05.2014 21:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficiently large, which allows loc...
CVE-2014-3145
- EPSS 0.06%
- Veröffentlicht 11.05.2014 21:55:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read...
CVE-2014-1737
- EPSS 0.05%
- Veröffentlicht 11.05.2014 21:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges b...
CVE-2014-1738
- EPSS 0.02%
- Veröffentlicht 11.05.2014 21:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from...