CVE-2014-1524
- EPSS 6.41%
- Veröffentlicht 30.04.2014 10:49:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers...
CVE-2014-1525
- EPSS 1.86%
- Veröffentlicht 30.04.2014 10:49:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execute arbitrary code or cause a de...
CVE-2014-1526
- EPSS 0.7%
- Veröffentlicht 30.04.2014 10:49:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operati...
- EPSS 1.26%
- Veröffentlicht 30.04.2014 10:49:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by...
CVE-2014-1529
- EPSS 1.32%
- Veröffentlicht 30.04.2014 10:49:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code i...
- EPSS 0.49%
- Veröffentlicht 28.04.2014 14:09:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a security group rule, which prevents further rules fr...
CVE-2011-3152
- EPSS 0.4%
- Veröffentlicht 27.04.2014 20:55:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the...
- EPSS 0.3%
- Veröffentlicht 23.04.2014 15:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all anonymous users, which allows remote attackers to bypass CSRF protections by reading the CSRF cookie...
- EPSS 3.96%
- Veröffentlicht 23.04.2014 15:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) FilePathField, (2) GenericIPAddressField, and (3) IPAddressField model field classes in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 do not properly perform type conversion, which allows remote att...
CVE-2014-0472
- EPSS 6.89%
- Veröffentlicht 23.04.2014 15:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The django.core.urlresolvers.reverse function in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 allows remote attackers to import and execute arbitrary Python modules by leveraging a view that constructs URL...