- EPSS 15.88%
- Veröffentlicht 17.12.2014 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities.
CVE-2014-9322
- EPSS 5.23%
- Veröffentlicht 17.12.2014 11:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access t...
CVE-2014-5353
- EPSS 0.87%
- Veröffentlicht 16.12.2014 23:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via...
- EPSS 1.73%
- Veröffentlicht 16.12.2014 18:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xdr_status_vector function in Firebird before 2.1.7 and 2.5.x before 2.5.3 SU1 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and crash) via an op_response action with a non-empty status.
- EPSS 36.87%
- Veröffentlicht 15.12.2014 18:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier does not properly handle attempts to send a large amount of ClientCutText data, which allows remote attackers to cause a denial of service (memor...
CVE-2014-6052
- EPSS 5.24%
- Veröffentlicht 15.12.2014 18:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HandleRFBServerMessage function in libvncclient/rfbproto.c in LibVNCServer 0.9.9 and earlier does not check certain malloc return values, which allows remote VNC servers to cause a denial of service (application crash) or possibly execute arbitra...
- EPSS 19.79%
- Veröffentlicht 15.12.2014 18:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
CVE-2014-8134
- EPSS 0.08%
- Veröffentlicht 12.12.2014 18:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted ...
CVE-2014-8602
- EPSS 9.76%
- Veröffentlicht 11.12.2014 02:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
CVE-2014-8737
- EPSS 0.06%
- Veröffentlicht 09.12.2014 23:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) ...