CVE-2014-9087
- EPSS 4.48%
- Veröffentlicht 01.12.2014 15:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer...
CVE-2014-9093
- EPSS 3.27%
- Veröffentlicht 26.11.2014 15:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
CVE-2014-7142
- EPSS 64.23%
- Veröffentlicht 26.11.2014 15:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.
CVE-2014-1421
- EPSS 0.01%
- Veröffentlicht 25.11.2014 15:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.
CVE-2014-7817
- EPSS 0.16%
- Veröffentlicht 24.11.2014 15:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
- EPSS 33.89%
- Veröffentlicht 20.11.2014 17:50:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.
CVE-2014-7824
- EPSS 0.09%
- Veröffentlicht 18.11.2014 15:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vu...
CVE-2014-5388
- EPSS 0.1%
- Veröffentlicht 15.11.2014 21:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corr...
- EPSS 3.4%
- Veröffentlicht 15.11.2014 20:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that tr...
CVE-2014-3707
- EPSS 0.23%
- Veröffentlicht 15.11.2014 20:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to r...