CVE-2014-7142
- EPSS 64.23%
- Veröffentlicht 26.11.2014 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.
CVE-2014-1421
- EPSS 0.01%
- Veröffentlicht 25.11.2014 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.
CVE-2014-7817
- EPSS 0.16%
- Veröffentlicht 24.11.2014 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
- EPSS 28.31%
- Veröffentlicht 20.11.2014 17:50:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow remote attackers to cause a denial of service (segmentation fault and crash) via a crafted length value in a Geonet frame.
CVE-2014-7824
- EPSS 0.09%
- Veröffentlicht 18.11.2014 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vu...
CVE-2014-5388
- EPSS 0.11%
- Veröffentlicht 15.11.2014 21:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the pci_read function in the ACPI PCI hotplug interface (hw/acpi/pcihp.c) in QEMU allows local guest users to obtain sensitive information and have other unspecified impact related to a crafted PCI device that triggers memory corr...
- EPSS 3.45%
- Veröffentlicht 15.11.2014 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that tr...
CVE-2014-3707
- EPSS 0.37%
- Veröffentlicht 15.11.2014 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to r...
- EPSS 5.23%
- Veröffentlicht 14.11.2014 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
CVE-2014-3689
- EPSS 0.09%
- Veröffentlicht 14.11.2014 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.