CVE-2014-0004
- EPSS 0.06%
- Veröffentlicht 11.03.2014 19:37:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in udisks before 1.0.5 and 2.x before 2.1.3 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long mount point.
CVE-2014-0101
- EPSS 3.09%
- Veröffentlicht 11.03.2014 13:01:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sctp_sf_do_5_1D_ce function in net/sctp/sm_statefuns.c in the Linux kernel through 3.13.6 does not validate certain auth_enable and auth_capable fields before making an sctp_sf_authenticate call, which allows remote attackers to cause a denial of...
CVE-2011-3153
- EPSS 0.05%
- Veröffentlicht 06.03.2014 15:55:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
dmrc.c in Light Display Manager (aka LightDM) before 1.1.1 allows local users to read arbitrary files via a symlink attack on ~/.dmrc.
CVE-2011-3634
- EPSS 0.16%
- Veröffentlicht 01.03.2014 00:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
methods/https.cc in apt before 0.8.11 accepts connections when the certificate host name fails validation and Verify-Host is enabled, which allows man-in-the-middle attackers to obtain repository credentials via unspecified vectors.
CVE-2014-1690
- EPSS 0.8%
- Veröffentlicht 28.02.2014 06:18:54
- Zuletzt bearbeitet 12.04.2025 10:46:40
The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet data is transmitted during use o...
CVE-2014-1874
- EPSS 0.09%
- Veröffentlicht 28.02.2014 06:18:54
- Zuletzt bearbeitet 12.04.2025 10:46:40
The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security cont...
CVE-2014-2038
- EPSS 0.05%
- Veröffentlicht 28.02.2014 06:18:54
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from ke...
- EPSS 21.22%
- Veröffentlicht 18.02.2014 19:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service (infinite recursion, CPU consumption, and crash) via a crafted indirect offset value in the magic of a file.
CVE-2013-7327
- EPSS 0.51%
- Veröffentlicht 18.02.2014 11:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via invalid imagecrop arguments t...
- EPSS 0.6%
- Veröffentlicht 10.02.2014 18:15:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection ...