CVE-2014-0211
- EPSS 2.43%
- Veröffentlicht 15.05.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow remote font servers to execute arbitrary code via a crafted xfs reply, wh...
CVE-2011-4407
- EPSS 0.13%
- Veröffentlicht 14.05.2014 00:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
ppa.py in Software Properties before 0.81.13.3 does not validate the server certificate when downloading PPA GPG key fingerprints, which allows man-in-the-middle (MITM) attackers to spoof GPG keys for a package repository.
CVE-2014-3122
- EPSS 0.09%
- Veröffentlicht 11.05.2014 21:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that req...
CVE-2014-3144
- EPSS 0.06%
- Veröffentlicht 11.05.2014 21:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) BPF_S_ANC_NLATTR and (2) BPF_S_ANC_NLATTR_NEST extension implementations in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 do not check whether a certain length value is sufficiently large, which allows loc...
CVE-2014-3145
- EPSS 0.06%
- Veröffentlicht 11.05.2014 21:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read...
CVE-2014-0190
- EPSS 1.08%
- Veröffentlicht 08.05.2014 14:29:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
CVE-2014-0056
- EPSS 0.22%
- Veröffentlicht 08.05.2014 14:29:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.
CVE-2013-4544
- EPSS 0.11%
- Veröffentlicht 08.05.2014 14:29:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly execute arbitrary code via vectors related to (1) RX or (2) TX queue numbers or (3) interrupt indices. NOTE: some of these detai...
CVE-2014-0196
- EPSS 63.84%
- Veröffentlicht 07.05.2014 10:55:04
- Zuletzt bearbeitet 22.10.2025 01:15:53
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or ...
CVE-2014-3203
- EPSS 0.07%
- Veröffentlicht 06.05.2014 14:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unity before 7.2.1, as used in Ubuntu 14.04, does not properly restrict access to the Dash when the lock screen is active, which allows physically proximate attackers to bypass the lock screen and execute arbitrary commands, as demonstrated by pressi...