CVE-2014-2328
- EPSS 1.13%
- Veröffentlicht 23.04.2014 15:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
lib/graph_export.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors.
- EPSS 0.73%
- Veröffentlicht 22.04.2014 13:06:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.
- EPSS 0.35%
- Veröffentlicht 22.04.2014 13:06:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
- EPSS 0.39%
- Veröffentlicht 20.04.2014 01:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arr...
CVE-2014-2287
- EPSS 22.86%
- Veröffentlicht 18.04.2014 22:14:38
- Zuletzt bearbeitet 12.04.2025 10:46:40
channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote ...
CVE-2014-2286
- EPSS 46.21%
- Veröffentlicht 18.04.2014 22:14:37
- Zuletzt bearbeitet 12.04.2025 10:46:40
main/http.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.x before 1.8.15-cert5 and 11.6 before 11.6-cert2, allows remote attackers to cause a denial of service (stack consum...
CVE-2013-6456
- EPSS 0.25%
- Veröffentlicht 15.04.2014 23:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virD...
- EPSS 14.64%
- Veröffentlicht 14.04.2014 22:38:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via...
CVE-2014-0160
- EPSS 94.48%
- Veröffentlicht 07.04.2014 22:55:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer ov...
CVE-2012-2095
- EPSS 0.6%
- Veröffentlicht 07.04.2014 15:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privileges via a crafted property name in a dbus message.