Количество 19 414
Количество 19 414
CVE-2014-5461
Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments.
CVE-2014-5282
CVE-2014-5278
CVE-2014-5277
CVE-2014-4607
Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run.
CVE-2014-3618
CVE-2014-3185
CVE-2014-10402
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401.
CVE-2014-0069
CVE-2014-0048
CVE-2014-0047
CVE-2013-7381
libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.
CVE-2013-6629
libjpeg Information Disclosure Vulnerability
CVE-2013-6418
PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.
CVE-2013-6381
CVE-2013-4420
CVE-2013-4416
The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply.
CVE-2013-4342
CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
CVE-2013-2094
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2014-5461 Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments. | 22% Средний | около 1 месяца назад | ||
CVSS3: 8.1 | 0% Низкий | больше 4 лет назад | ||
CVSS3: 5.3 | 0% Низкий | больше 4 лет назад | ||
1% Низкий | больше 4 лет назад | |||
CVE-2014-4607 Integer overflow in the LZO algorithm variant in Oberhumer liblzo2 and lzo-2 before 2.07 on 32-bit platforms might allow remote attackers to execute arbitrary code via a crafted Literal Run. | 10% Средний | 7 месяцев назад | ||
10% Низкий | больше 4 лет назад | |||
0% Низкий | около 2 лет назад | |||
CVE-2014-10402 An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue exists because of an incomplete fix for CVE-2014-10401. | CVSS3: 6.1 | 0% Низкий | 7 месяцев назад | |
0% Низкий | около 2 лет назад | |||
CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | ||
CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | ||
CVE-2013-7381 libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify. | CVSS3: 9.8 | 2% Низкий | 6 месяцев назад | |
CVE-2013-6629 libjpeg Information Disclosure Vulnerability | CVSS3: 4.7 | 0% Низкий | почти 9 лет назад | |
CVE-2013-6418 PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate. | 0% Низкий | 7 месяцев назад | ||
0% Низкий | около 2 лет назад | |||
0% Низкий | больше 5 лет назад | |||
CVE-2013-4416 The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a denial of service (domain shutdown) via a large message reply. | 0% Низкий | 7 месяцев назад | ||
15% Средний | около 3 лет назад | |||
CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability | 80% Высокий | около 4 лет назад | ||
CVE-2013-2094 The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type which allows local users to gain privileges via a crafted perf_event_open system call. | CVSS3: 8.4 | 66% Средний | около 2 лет назад |
Уязвимостей на страницу