CVE-2014-7230
- EPSS 0.12%
- Veröffentlicht 08.10.2014 19:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
- EPSS 2.82%
- Veröffentlicht 07.10.2014 14:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.
- EPSS 8.76%
- Veröffentlicht 07.10.2014 14:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
snmplib/mib.c in net-snmp 5.7.0 and earlier, when the -OQ option is used, allows remote attackers to cause a denial of service (snmptrapd crash) via a crafted SNMP trap message, which triggers a conversion to the variable type designated in the MIB f...
CVE-2014-6054
- EPSS 34.58%
- Veröffentlicht 06.10.2014 14:55:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) Palm...
CVE-2014-3633
- EPSS 2.92%
- Veröffentlicht 06.10.2014 14:55:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image, allows remote attackers to cause a denial of service (crash) or read sensitive heap information via ...
- EPSS 0.57%
- Veröffentlicht 02.10.2014 14:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
- EPSS 0.43%
- Veröffentlicht 02.10.2014 14:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the pub...
CVE-2014-3186
- EPSS 0.09%
- Veröffentlicht 28.09.2014 10:55:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of...
CVE-2014-6416
- EPSS 2.84%
- Veröffentlicht 28.09.2014 10:55:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, allows remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a long unencrypted auth ticket.
CVE-2014-6418
- EPSS 3.97%
- Veröffentlicht 28.09.2014 10:55:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from t...