CVE-2014-3153
- EPSS 76.04%
- Veröffentlicht 07.06.2014 14:55:27
- Zuletzt bearbeitet 22.10.2025 01:15:56
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe wai...
CVE-2013-6433
- EPSS 1.89%
- Veröffentlicht 02.06.2014 15:55:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration file.
- EPSS 0.4%
- Veröffentlicht 01.06.2014 04:29:34
- Zuletzt bearbeitet 12.04.2025 10:46:40
sosreport in Red Hat sos 1.7 and earlier on Red Hat Enterprise Linux (RHEL) 5 produces an archive with an fstab file potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which migh...
CVE-2012-6648
- EPSS 0.06%
- Veröffentlicht 22.05.2014 23:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
gdm/guest-session-cleanup.sh in gdm-guest-session 0.24 and earlier, as used in Ubuntu Linux 10.04 LTS, 10.10, and 11.04, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT from CVE-...
CVE-2012-0943
- EPSS 0.22%
- Veröffentlicht 22.05.2014 23:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
debian/guest-account in Light Display Manager (lightdm) 1.0.x before 1.0.6 and 1.1.x before 1.1.7, as used in Ubuntu Linux 11.10, allows local users to delete arbitrary files via a space in the name of a file in /tmp. NOTE: this identifier was SPLIT...
- EPSS 4.37%
- Veröffentlicht 21.05.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.
CVE-2014-3730
- EPSS 0.99%
- Veröffentlicht 16.05.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.util.http.is_safe_url function in Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly validate URLs, which allows remote attackers to conduct open redirect attacks via a malformed URL, as de...
CVE-2014-1418
- EPSS 0.51%
- Veröffentlicht 16.05.2014 15:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Django 1.4 before 1.4.13, 1.5 before 1.5.8, 1.6 before 1.6.5, and 1.7 before 1.7b4 does not properly include the (1) Vary: Cookie or (2) Cache-Control header in responses, which allows remote attackers to obtain sensitive information or poison the ca...
CVE-2014-0209
- EPSS 0.17%
- Veröffentlicht 15.05.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privileges by adding a directory with a large fonts.dir or fonts.alias file ...
CVE-2014-0210
- EPSS 2.11%
- Veröffentlicht 15.05.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple buffer overflows in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs protocol reply to the (1) _fs_recv_conn_setup, (2) fs_read_open_font, (3) fs_read_query_info, ...