CVE-2014-8150
- EPSS 1.23%
- Veröffentlicht 15.01.2015 15:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL.
CVE-2014-9585
- EPSS 0.05%
- Veröffentlicht 09.01.2015 21:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the ...
CVE-2014-9584
- EPSS 0.13%
- Veröffentlicht 09.01.2015 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel...
CVE-2014-9529
- EPSS 0.11%
- Veröffentlicht 09.01.2015 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that...
- EPSS 7.91%
- Veröffentlicht 07.01.2015 19:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.
CVE-2014-1425
- EPSS 0.05%
- Veröffentlicht 07.01.2015 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
cmanager 0.32 does not properly enforce nesting when modifying cgroup properties, which allows local users to set cgroup values for all cgroups via unspecified vectors.
CVE-2014-8109
- EPSS 15.83%
- Veröffentlicht 29.12.2014 23:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows rem...
- EPSS 3.29%
- Veröffentlicht 29.12.2014 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.
CVE-2014-8136
- EPSS 0.13%
- Veröffentlicht 19.12.2014 15:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors.
- EPSS 16.45%
- Veröffentlicht 17.12.2014 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors.