- EPSS 0.67%
- Veröffentlicht 10.02.2014 18:15:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection ...
CVE-2012-3406
- EPSS 0.87%
- Veröffentlicht 10.02.2014 18:15:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers...
CVE-2013-6393
- EPSS 8.06%
- Veröffentlicht 06.02.2014 22:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML docum...
CVE-2013-2038
- EPSS 2.01%
- Veröffentlicht 06.02.2014 17:00:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpreted sentence that lacks certain fields and a termina...
CVE-2014-1487
- EPSS 0.61%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 25.11.2025 17:50:16
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information v...
- EPSS 1.09%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation...
CVE-2014-1489
- EPSS 1.25%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
CVE-2014-1490
- EPSS 1.14%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 25.11.2025 17:50:16
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to ca...
CVE-2014-1491
- EPSS 0.6%
- Veröffentlicht 06.02.2014 05:44:25
- Zuletzt bearbeitet 25.11.2025 17:50:16
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellma...
CVE-2014-1477
- EPSS 0.85%
- Veröffentlicht 06.02.2014 05:44:24
- Zuletzt bearbeitet 25.11.2025 17:50:16
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and app...