CVE-2014-7970
- EPSS 0.04%
- Veröffentlicht 13.10.2014 10:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in bo...
- EPSS 4.81%
- Veröffentlicht 10.10.2014 10:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cache_merge_headers_out function in modules/cache/cache_util.c in the mod_cache module in the Apache HTTP Server before 2.4.11 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty HTTP...
CVE-2014-7230
- EPSS 0.12%
- Veröffentlicht 08.10.2014 19:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
- EPSS 3.2%
- Veröffentlicht 07.10.2014 14:55:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
- EPSS 7.5%
- Veröffentlicht 07.10.2014 14:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB f...
CVE-2014-6054
- EPSS 37.75%
- Veröffentlicht 06.10.2014 14:55:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) Palm...
CVE-2014-3633
- EPSS 2.86%
- Veröffentlicht 06.10.2014 14:55:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via ...
- EPSS 0.57%
- Veröffentlicht 02.10.2014 14:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
- EPSS 0.43%
- Veröffentlicht 02.10.2014 14:55:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the pub...
CVE-2014-3186
- EPSS 0.12%
- Veröffentlicht 28.09.2014 10:55:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of...