CVE-2013-6456
- EPSS 0.28%
- Veröffentlicht 15.04.2014 23:55:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virD...
- EPSS 10.73%
- Veröffentlicht 14.04.2014 22:38:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via...
CVE-2014-0160
- EPSS 94.46%
- Veröffentlicht 07.04.2014 22:55:03
- Zuletzt bearbeitet 22.10.2025 01:15:53
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer ov...
CVE-2012-2095
- EPSS 0.56%
- Veröffentlicht 07.04.2014 15:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SetWiredProperty function in the D-Bus interface in WICD before 1.7.2 allows local users to write arbitrary configuration settings and gain privileges via a crafted property name in a dbus message.
CVE-2014-2678
- EPSS 0.09%
- Veröffentlicht 01.04.2014 06:35:53
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS s...
CVE-2014-2326
- EPSS 1.27%
- Veröffentlicht 27.03.2014 16:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-6474
- EPSS 20.77%
- Veröffentlicht 14.03.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
CVE-2013-6475
- EPSS 20.68%
- Veröffentlicht 14.03.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer...
CVE-2013-6476
- EPSS 0.29%
- Veröffentlicht 14.03.2014 15:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file.
CVE-2011-4930
- EPSS 0.1%
- Veröffentlicht 10.02.2014 18:15:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to la...