CVE-2015-0374
- EPSS 0.24%
- Veröffentlicht 21.01.2015 18:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.
- EPSS 13.26%
- Veröffentlicht 21.01.2015 18:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
CVE-2014-6568
- EPSS 0.39%
- Veröffentlicht 21.01.2015 15:28:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
CVE-2014-9604
- EPSS 0.65%
- Veröffentlicht 16.01.2015 20:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video d...
- EPSS 5.84%
- Veröffentlicht 16.01.2015 16:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
ModelMultipleChoiceField in Django 1.6.x before 1.6.10 and 1.7.x before 1.7.3, when show_hidden_initial is set to True, allows remote attackers to cause a denial of service by submitting duplicate values, which triggers a large number of SQL queries.
- EPSS 9.15%
- Veröffentlicht 16.01.2015 16:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.views.static.serve view in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 reads files an entire line at a time, which allows remote attackers to cause a denial of service (memory consumption) via a long line in a file.
CVE-2015-0220
- EPSS 2.55%
- Veröffentlicht 16.01.2015 16:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.util.http.is_safe_url function in Django before 1.4.18, 1.6.x before 1.6.10, and 1.7.x before 1.7.3 does not properly handle leading whitespaces, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL...
CVE-2014-9496
- EPSS 0.1%
- Veröffentlicht 16.01.2015 16:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.
CVE-2014-9471
- EPSS 8.47%
- Veröffentlicht 16.01.2015 16:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date comman...
- EPSS 6.06%
- Veröffentlicht 15.01.2015 15:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.