CVE-2014-0195
- EPSS 92.75%
- Veröffentlicht 05.06.2014 21:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary c...
CVE-2014-0221
- EPSS 83.02%
- Veröffentlicht 05.06.2014 21:55:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS...
CVE-2014-3956
- EPSS 0.1%
- Veröffentlicht 04.06.2014 11:19:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom ma...
- EPSS 2.37%
- Veröffentlicht 02.06.2014 15:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
CVE-2014-3152
- EPSS 3.2%
- Veröffentlicht 21.05.2014 11:14:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspeci...
- EPSS 0.25%
- Veröffentlicht 08.05.2014 14:29:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.
CVE-2014-1685
- EPSS 0.39%
- Veröffentlicht 08.05.2014 14:29:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
CVE-2014-0190
- EPSS 1.08%
- Veröffentlicht 08.05.2014 14:29:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.
CVE-2014-0198
- EPSS 30.89%
- Veröffentlicht 06.05.2014 10:44:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL...
CVE-2010-5109
- EPSS 1.24%
- Veröffentlicht 05.05.2014 17:06:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of service (crash) via a crafted TNEF file, which triggers a buffer overflow.