CVE-2014-5029
- EPSS 0.05%
- Veröffentlicht 29.07.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The web interface in CUPS 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/ and language[0] set to null. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-...
CVE-2014-5030
- EPSS 0.05%
- Veröffentlicht 29.07.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
CUPS before 2.0 allows local users to read arbitrary files via a symlink attack on (1) index.html, (2) index.class, (3) index.pl, (4) index.php, (5) index.pyc, or (6) index.py.
- EPSS 1.62%
- Veröffentlicht 29.07.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive information via unspecified vectors.
CVE-2014-1419
- EPSS 0.04%
- Veröffentlicht 24.07.2014 14:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors.
CVE-2014-3537
- EPSS 0.05%
- Veröffentlicht 23.07.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
CVE-2014-4167
- EPSS 0.56%
- Veröffentlicht 11.07.2014 14:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.
CVE-2014-4699
- EPSS 1.33%
- Veröffentlicht 09.07.2014 11:07:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain p...
- EPSS 6.61%
- Veröffentlicht 03.07.2014 17:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx.
- EPSS 14.14%
- Veröffentlicht 03.07.2014 04:22:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
CVE-2014-4608
- EPSS 8.6%
- Veröffentlicht 03.07.2014 04:22:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a cra...